Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2024-4340Uncontrolled Recursion in Project Sqlparse

Severity
7.5HIGHNVD
EPSS
16.0%
top 5.23%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 30
Latest updateFeb 12

Description

Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/sqlparse< sqlparse 0.4.2-1+deb12u1 (bookworm)
Debiansqlparse_project/sqlparse< 0.4.1-1+deb11u1+3

🔴Vulnerability Details

3
OSV
CVE-2024-4340: Passing a heavily nested list to sqlparse2024-04-30
GHSA
sqlparse parsing heavily nested list leads to Denial of Service2024-04-15
OSV
sqlparse parsing heavily nested list leads to Denial of Service2024-04-15

💥Exploits & PoCs

1
Nuclei
sqlparse - Denial of Service

📋Vendor Advisories

3
Ubuntu
SQL parse vulnerability2024-05-13
Red Hat
sqlparse: parsing heavily nested list leads to denial of service2024-04-30
Debian
CVE-2024-4340: sqlparse - Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service d...2024

📄Research Papers

1
arXiv
From CVE Entries to Verifiable Exploits: An Automated Multi-Agent Framework for Reproducing CVEs2026-02-12