Back

MEDIUM

Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser

Published Jul 30, 2026

Description

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse library integration. The affected regular expression contains overlapping disjunctions that share a common outer quantifier. An authenticated attacker can exploit this by sending a maliciously crafted input string (specifically a long sequence of backslashes or similar characters) to endpoints that process SQL queries

This issue affects Apache Superset: before 6.0.0.

Users are recommended to upgrade to version 6.0.0, which fixes the issue. 

Workarounds: ● WAF Rules: Implement Web Application Firewall (WAF) rules to detect and block requests containing excessively long sequences of backslashes or suspicious repeated patterns in the queries.extras.where parameter. ● Rate Limiting: Ensure strict rate limiting is applied to the /api/v1/chart/data endpoint to reduce the impact of potential attacks.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jul 30, 2026
Updated Jul 30, 2026
Reserved Jan 19, 2026
CISA Vulnrichment
Updated Jul 30, 2026
NVD
Status Analyzed
Modified Aug 5, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner apache
Published Jul 30, 2026
Updated Jul 30, 2026
Exploited since n/a
EUVD-2026-51187