StackRadar

CVE-2023-30608

High

Advisory

Published 18 Apr 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
60th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,781 indexed, latest versions
Container images
52
deployed by those charts
Fix available
2 of 2
affected packages

sqlparse contains a regular expression that is vulnerable to Regular Expression Denial of Service

Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 52 images.

Affected packageAffected versionsFixed inImages
sqlparsedeb0.2.4-30.2.4-3ubuntu0.11
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+4 more0.4.452
OSV records
UBUNTU-CVE-2023-30608GHSA-rrm6-wvj7-cwh2
Also known as
PYSEC-2023-87, USN-6064-1

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.4.4

Open the chart page →

5,456
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
sqlparse@0.4.2
0.4.4

Open the chart page →

22,084
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
sqlparse@0.3.1
0.4.4

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
sqlparse@0.2.4-3
sqlparse@0.2.4
0.2.4-3ubuntu0.1
0.4.4

Open the chart page →

30,687
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.4.4

Open the chart page →

2,060
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.4.4

Open the chart page →

3,392

Container images carrying it

52 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
weblate/weblate:3.11.3-182848df56ecd
sqlparse@0.3.1
0.4.4
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
sqlparse@0.4.2
0.4.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.