CVE-2024-4340

Aliases:GHSA-2m57-hf25-phgg
Advisory lineage Upstream: 0 Downstream: 12
Deferred
Published: 30 Apr 2024, 14:23
Last modified:03 Nov 2025, 22:05

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
10.88% MEDIUM
11% probability -6.16%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Apr 2024, 14:23
Published
Vulnerability first disclosed
03 Nov 2025, 22:05
Last Modified
Vulnerability information updated

Description

Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 10.88% Percentile: 94%

Techniques & Countermeasures

  • CWE-674Uncontrolled Recursion

    The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Systems

  • PyPIsqlparse

    < 0.5.0

References (8)