What is CVE-2026-23985?
This is a Regular Expression Denial of Service (ReDoS) vulnerability in Apache Superset versions 1.5.0 through 5.0.0, found in the SQL_REGEX used for parsing SQL statements via the sqlparse library. An attacker can exhaust server resources with crafted queries. Upgrading Superset to the latest version is recommended.
Azərbaycanca: Bu, Apache Superset-in 1.5.0-dən 5.0.0-dək versiyalarında sqlparse kitabxanası ilə SQL sorğularının təhlili üçün istifadə edilən SQL_REGEX komponentində mövcud olan Regular Expression Denial of Service (ReDoS) zəifliyidir. Təcavüzkar xüsusi hazırlanmış sorğularla server resurslarını tükədə bilər. Superset-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which versions of Apache Superset are affected by CVE-2026-23985?
Apache Superset versions 1.5.0 through 5.0.0 are affected by this vulnerability.
What type of security issue is CVE-2026-23985 and how can it be resolved?
It is a Regular Expression Denial of Service (ReDoS) vulnerability in the SQL_REGEX component, arising through the sqlparse library. An attacker can exhaust server resources with crafted queries. Upgrading Superset to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.