SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
A sub-2MB valid SQL query drives SQLGlot past 1.5GB of memory in Imperva tests
Imperva found that a syntactically valid SQL query under 2MB can drive the SQLGlot parser past 1.5GB of memory, about 750 times the input. Tools that parse user or model-supplied SQL before the database sees it carry the same exposure until they upgrade.
The Watch · Security desk

What happened
- In both parsers, a valid query nested more than 50 levels deep exhausted the call stack, crashing Python with a RecursionError and, under higher concurrency, a segfault.
- SQLFluff showed the same memory inflation as SQLGlot, using more than 1GB of RAM on a query with a width of 5,000.
- Apache Superset, a project with about 75,000 GitHub stars that runs on SQLGlot, appears in Imperva's write-up under the heading 'Complete Service Outage'.
- Imperva reported each issue to the maintainers and helped write fixes that now ship upstream; the SQLFluff findings are CVE-2026-46373 and CVE-2026-46374.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Any Python service that validates, transpiles or lints submitted SQL can be crashed by anyone allowed to submit a query, because the parser runs before the database applies its own checks.
- decision Request-size limits set for normal traffic will let a 2MB payload through, so teams that cannot upgrade yet have to put their own nesting and memory caps in front of the parser.
- constraint When the parser runs inside the web process, the application stays up only as long as the parser survives its worst input, because a parser crash can take the application down with it.
- precedent Imperva expects the same root causes in other parsers and other languages, so maintainers of those parsers now have two published failure patterns to test against.
Imperva's researchers wrote that the trigger is "Just normal-looking SQL that happens to be shaped in the wrong way." [2] The payloads contain neither injection nor malformed syntax [3]. A filter that looks for either one lets them through. According to Imperva, any database would reject a query nested that deeply as absurd, but the parser that sits in front of the database still tries to parse it [6]. Neither library limited recursion depth when Imperva tested it [5].
Width drives the memory failure as much as depth does. Tokenization first splits the payload into hundreds of thousands of pieces [11]. Each token, down to a single dot, then becomes a Python object holding type information, position tracking and a parent reference [10]. A compact query with thousands of columns and deep expression chains produces millions of tree nodes [12]. According to Imperva, the OOM killer then ends the process, or the process hangs and starves everything else on the machine [12].
I'd rate this as easy to trigger but narrow in reach. The attacker needs a text field that passes SQL to SQLGlot or SQLFluff, and a valid string to put in it [3]. Database permissions never come into play, because the parser runs before the query reaches the database [17].
Imperva also says these parsers increasingly sit inside LLM-integrated tools that generate SQL [19]. In those tools the parser stands between the database and whatever SQL it receives, whether a model wrote it or a user pasted it in [17][19]. The available text of the post shows SQL being submitted directly. It does not show a model being steered into writing the payload, and it does not say whether the Superset route needs a logged-in user.
The findings come from Imperva's own testing of the two libraries [1]. Until a deployment picks up the upstream fix, the stopgap is the one Imperva proposes for the parsers themselves: a hard nesting limit of around 30 levels and a graceful abort [7]. A depth cap does not limit column count, so the memory case stays open [12].
What to watch
- Whether SQLGlot gets its own CVE ID or an advisory naming a fixed version, so dependency scanners can flag vulnerable installs.
- Imperva's other downstream examples beyond Superset, and whether any of them expose the parser to unauthenticated users.
- A Superset advisory or release note that names the SQLGlot fix and the version operators need.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Imperva's research focused on two Python-based SQL parsers, SQLGlot and SQLFluff, each with around 10k GitHub stars.
- [2]
Just normal-looking SQL that happens to be shaped in the wrong way.
- [3]
The parsers are susceptible to resource exhaustion from syntactically valid SQL queries that are not injection and not malformed input.
- [4]
Feeding a deeply nested query to the parsers crashes the Python interpreter with a RecursionError, and at higher concurrency it segfaults; at 50+ levels of nesting the recursive descent parser exhausts the call stack.
- [5]
Both SQLGlot and SQLFluff attempt to parse deeply nested queries without any depth limit.
- [6]
Any database would reject the deeply nested query for being absurd, but a parser's job is to parse it.
- [7]
Imperva's suggested fix is to enforce a maximum recursion depth (e.g., 30 levels) and abort gracefully.
- [8]
In SQLGlot, a SQL string under 2MB in size demanded over 1.5GB of RAM to parse, roughly a 750x amplification ratio.
- [9]
SQLFluff showed the same pattern: at width=5000 it consumed over 1GB.
- [10]
Each token (literal, identifier, operator, dot) becomes a Python object carrying type information, position tracking and parent references.
- [11]
Tokenization splits the payload string into hundreds of thousands of pieces before AST construction.
- [12]
A compact input with thousands of columns and deep expression chains generates millions of AST nodes; the process is killed by the OOM killer or hangs until it starves out everything else on the machine.
- [13]
Imperva describes a 2MB string as a perfectly normal payload by any standard.
- [14]
When the parser crashes, the application may crash with it; Imperva traced this cascade through several major projects.
- [15]
Apache Superset (~75k stars) uses SQLGlot under the hood and is listed in Imperva's post under the heading 'Complete Service Outage'.
- [16]
Imperva reported every issue to the maintainers and contributed to fixes that now ship upstream; the SQLFluff findings were assigned CVE-2026-46373 and CVE-2026-46374.
- [17]
SQL parsers validate queries before they reach the database, transpile between dialects, and lint codebases for style violations.
- [18]
Imperva believes the underlying issues are relevant to other parsers and other programming languages as well.
- [19]
SQL parsers increasingly power AI-driven SQL generation in LLM-integrated data tools.
Sources
1 independent publisher whose own reporting we read for this story.
- imperva.comThe Hidden DoS Vector in SQL Parsers
1 article · October 5, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.