CVE-2026-21892

EUVD-2026-1034
Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsafe string formatting (Python % operator) with user-supplied input (workflow_id) directly from URL routes. This allows an unauthenticated attacker with access to the visualization dashboard to inject arbitrary SQL commands, potentially leading to data exfiltration or denial of service against the monitoring database. Version 2026.01.05 fixes the issue.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 15.25%
Affected Products (NVD)
VendorProductVersion
uchicagoparsl
𝑥
< 2026.01.05
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-parsl
forky
2026.07.27+ds-1
fixed
sid
2026.07.27+ds-2
fixed
trixie
2025.01.13+ds-1+deb13u1
fixed
trixie (security)
2025.01.13+ds-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-parsl
jammy
dne
noble
Fixed 2024.02.26+ds-1ubuntu0.1~esm1
released
plucky
ignored
questing
ignored
resolute
not-affected