CVE-2026-21892: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-21892 is a SQL Injection vulnerability in the parsl-visualize component of Parsl (Python Parallel Scripting Library), a parallel scripting framework developed at the University of Chicago. The flaw affects all Parsl versions prior to 2026.01.05 (specifically confirmed in version 2025.12.1) and was published on January 6, 2026, with NVD publication on January 8, 2026. An unauthenticated attacker with network access to the visualization dashboard can inject arbitrary SQL commands via the workflow_id URL parameter. The CNA (GitHub) assigned a CVSS v3.1 score of 5.3 (Medium), while NVD's independent assessment rates it 7.3 (High) (Github Advisory, Parsl Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), located in parsl/monitoring/visualization/views.py. Multiple Flask route handlers pass the workflow_id URL parameter directly into raw SQL query strings using Python's % string formatting operator without any sanitization or parameterization. Two specific vulnerable patterns were identified: WHERE task.run_id='%s'" % (workflow_id) in the DAG view handler, and a similar pattern in the resource usage view using pd.read_sql_query("...run_id='%s'..." % (workflow_id, workflow_id), db.engine). The attack requires no authentication and no user interaction — only network access to the running parsl-visualize server (Github Advisory, Patch Commit).

Impact

Successful exploitation can lead to data exfiltration via UNION-based injection, allowing an attacker to dump the entire contents of the Parsl monitoring database, which may include sensitive environment variables, task parameters, and host information. An attacker can also bypass workflow-level access controls using boolean injection (e.g., ' OR '1'='1) to view data from workflows they are not authorized to access. Additionally, time-based or resource-intensive SQL payloads (e.g., using randomblob) can cause denial of service against the visualization server or the underlying SQLite database (Github Advisory).

Exploitability

A proof-of-concept (PoC) demonstrating boolean-based blind SQL injection is publicly documented in the GitHub Security Advisory, making exploitation straightforward for any attacker with access to the dashboard. The advisory was tagged as an "Exploit" reference by both CISA-ADP and NVD. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.038% (Feedly data) to 0.106% (GitHub Advisory), placing it in the 28th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Parsl Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or locally accessible parsl-visualize servers (default port 8080) using network scanning tools or by checking for exposed Parsl monitoring dashboards. Confirm the instance is running a vulnerable version prior to 2026.01.05.
  2. Identify a workflow ID: Browse the visualization dashboard to find a valid workflow_id (e.g., a UUID or default-run), or attempt common identifiers. A valid ID is needed as the base for injection.
  3. Confirm SQL injection (Boolean-based Blind): Send a crafted request with a false condition to verify injection control:
    http://<host>:8080/workflow/' AND '1'='0/dag_group_by_states
    An empty graph confirms the false condition was evaluated. Then confirm with a true condition:
    http://<host>:8080/workflow/' AND '1'='1/dag_group_by_states
    A populated graph confirms SQL injection is active.
  4. Data exfiltration via UNION injection: Craft a UNION-based payload to enumerate database tables and extract sensitive data (e.g., environment variables, task parameters, host info) stored in the monitoring database.
  5. Denial of Service (optional): Inject resource-intensive SQL functions (e.g., randomblob in SQLite) to degrade or crash the visualization server or database (Github Advisory, Parsl Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET requests to /workflow/<id>/dag_group_by_states or /workflow/<id>/ endpoints where <id> contains SQL metacharacters such as ', %20AND%20, UNION, SELECT, OR, or randomblob.
  • Logs: Web server access logs showing URL-encoded SQL payloads in the workflow_id path segment (e.g., %27, %20AND%20, UNION+SELECT); repeated requests to visualization endpoints with varying injected conditions.
  • Application Behavior: Visualization dashboard returning empty graphs followed by populated graphs in rapid succession (indicative of boolean-based blind SQLi probing); unexpected database errors or crashes in the Parsl monitoring database.

Mitigation and workarounds

Upgrade Parsl to version 2026.01.05 or later, which fixes the vulnerability by replacing unsafe Python % string formatting with SQLAlchemy parameterized queries using named bind parameters (:run_id) and sqlalchemy.text() (Patch Commit). If immediate upgrade is not possible, restrict network access to the parsl-visualize server so it is only accessible to trusted users (e.g., via firewall rules or binding to localhost). Do not expose the parsl-visualize dashboard to untrusted networks, as it is designed for internal monitoring use (Github Advisory).

Community reactions

The vulnerability was reported by security researcher viralvaghela and acknowledged by Parsl maintainer benclifford, who noted in the patch commit that in the default configuration the practical security impact may be limited because the parsl-visualize database is already intended to be public and SQLite restricts multi-statement execution (Patch Commit). The advisory was picked up by Debian security advisories and Linux security news outlets, and detection plugins were added by Nessus (Tenable) and Qualys shortly after disclosure (Github Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

python-parsl: 2026.01.05+ds-1

Fixed

trixie

python-parsl: 2025.01.13+ds-1+deb13u1

Fixed

Ubuntu

Fixed

devel

python-parsl

Not Affected

noble

python-parsl

Affected

noble (esm-apps)

python-parsl: 2024.02.26+ds-1ubuntu0.1~esm1

Fixed

resolute

python-parsl

Not Affected

resolute (esm-apps)

python-parsl

Not Affected

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management