THREATOPS
THREAT OPSThreat News › CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser

CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser

medoss_secPublished 2026-07-30

<p>Posted by Daniel Gaspar on Jul 30</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache Superset before 6.0.0<br /> <br /> Description:<br /> <br /> A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. <br /> The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/332