This document outlines the security model for sqlparser-rs and how to
report vulnerabilities.
sqlparser-rs parses SQL text, which is often untrusted input (e.g., a query
string from a user or external system). The parser is expected to reject invalid
or malformed SQL with an error.
Unexpected behavior triggered by malformed or adversarial input is generally considered a bug, not a security vulnerability, unless it is exploitable* and could allow an attacker to
- Execute arbitrary code (Remote Code Execution);
- Exfiltrate sensitive information from process memory (Information Disclosure);
For example, panics, crashes, stack overflows, excessive resource consumption, or infinite loops are generally considered bugs, unless they can be exploited to achieve one of the above security goals. If that exploitation path is unclear, the issue should likely be reported as a bug.
We treat all bugs seriously and welcome help fixing them. If you find a bug that does not meet the criteria for a security vulnerability, please report it in the public issue tracker.
For security vulnerabilities, do not file a public issue. Follow the ASF security reporting process by emailing security@apache.org.
Include in your report:
- A clear description and minimal reproducer.
- Affected crates and versions.
- A demonstration of the potential impact.