StackRadar

CVE-2024-4340

High

Advisory

Published 15 Apr 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.032
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
70
of 17,781 indexed, latest versions
Container images
69
deployed by those charts
Fix available
1 of 1
affected package

sqlparse parsing heavily nested list leads to Denial of Service

Carried by container images the latest versions of 70 of 17,781 indexed charts deploy, on 69 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+5 more0.5.069
OSV records
GHSA-2m57-hf25-phgg
Also known as
PYSEC-2026-1940

Charts affected

70 by stars
ChartLatestAffected imagesRadar Score
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
sqlparse@0.4.4
0.5.0

Open the chart page →

11,367
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
sqlparse@0.4.2
0.5.0

Open the chart page →

9,145
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.5.0

Open the chart page →

5,851
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
sqlparse@0.3.1
0.5.0

Open the chart page →

30,326
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.5.0

Open the chart page →

52,919
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
taigaio/taiga-back:6.4.29f97323cc150
sqlparse@0.4.1
0.5.0

Open the chart page →

7,255
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
dpage/pgadmin4:7.537946e4f3e7b
sqlparse@0.4.4
0.5.0

Open the chart page →

14,546
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
redislabs/redisinsight:1.14.0b03ab1426d0d
sqlparse@0.4.4
0.5.0

Open the chart page →

13,874
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
flagsmith/flagsmith-api:v2.6.0fd58556339a4
sqlparse@0.4.1
0.5.0

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
sqlparse@0.4.2
0.5.0
kobotoolbox/kpi:2.022.24dbcacc01bccd4
sqlparse@0.4.2
0.5.0

Open the chart page →

18,517
open-zaakopen-zaak0.8.01 of 3See more

open-zaak open-zaak 0.8.0

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
openzaak/open-zaak:1.6.02ca2ea6e0ae9
sqlparse@0.4.2
0.5.0

Open the chart page →

4,045
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.5.0

Open the chart page →

7,984
archerydoubanVerified publisher0.4.31 of 6See more

archery douban 0.4.3

1 of the 6 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
hhyo/archery:v1.9.11aa41843419e
sqlparse@0.4.3
0.5.0

Open the chart page →

5,853
pgadmin4folio-org1.2.301 of 1See more

pgadmin4 folio-org 1.2.30

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.22b1f00b8163cf
sqlparse@0.2.4
0.5.0

Open the chart page →

2,034
healthchecksgeek-cookbookVerified publisher4.4.21 of 1See more

healthchecks geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
linuxserver/healthchecks:version-v1.20.050792a72fc71
sqlparse@0.4.1
0.5.0

Open the chart page →

1,667
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
sqlparse@0.4.2
0.5.0

Open the chart page →

3,924
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
sqlparse@0.4.2
0.5.0

Open the chart page →

7,801
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
sqlparse@0.3.0
0.5.0

Open the chart page →

7,129
mlflow-controllermlflow-deployment-controller0.1.82 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

2 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
sqlparse@0.4.3
0.5.0
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
sqlparse@0.4.3
0.5.0

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
sqlparse@0.4.3
0.5.0

Open the chart page →

5,804
open-notificatiesopen-zaak0.7.01 of 4See more

open-notificaties open-zaak 0.7.0

1 of the 4 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
openzaak/open-notificaties:1.3.02e65313b9b10
sqlparse@0.4.2
0.5.0

Open the chart page →

2,850
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
sqlparse@0.4.3
0.5.0

Open the chart page →

2,236
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
sqlparse@0.2.2
0.5.0

Open the chart page →

24,930
ddosifyanteonVerified publisher1.7.53 of 13See more

ddosify anteon 1.7.5

3 of the 13 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlparse@0.4.4
0.5.0
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlparse@0.4.4
0.5.0
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
sqlparse@0.4.4
0.5.0

Open the chart page →

25,669
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.5.0

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.5.0

Open the chart page →

2,418
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
sqlparse@0.4.1
0.5.0
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
sqlparse@0.4.1
0.5.0

Open the chart page →

22,568
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.5.0

Open the chart page →

10,061
shynetatrox0.1.11 of 1See more

shynet atrox 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.12.0e821e31140f7
sqlparse@0.4.2
0.5.0

Open the chart page →

5,507
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
sqlparse@0.4.1
0.5.0

Open the chart page →

22,891
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
sqlparse@0.4.4
0.5.0

Open the chart page →

2,507
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
sqlparse@0.2.4
0.5.0

Open the chart page →

5,060
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.5.0

Open the chart page →

12,457
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.5.0

Open the chart page →

12,131
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.5.0

Open the chart page →

11,592
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
sqlparse@0.4.2
0.5.0

Open the chart page →

16,069
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
sqlparse@0.1.16
0.5.0

Open the chart page →

70,895
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
sqlparse@0.4.4
0.5.0

Open the chart page →

11,335
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.5.0

Open the chart page →

4,422
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
sqlparse@0.4.3
0.5.0

Open the chart page →

14,856
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
alexeyr7/sf-test-app:latestdf0b41fdbd53
sqlparse@0.4.2
0.5.0

Open the chart page →

2,548
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
sqlparse@0.4.4
0.5.0
codecov/self-hosted-worker:24.4.1837f546b479b
sqlparse@0.4.4
0.5.0

Open the chart page →

24,917
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
sqlparse@0.4.3
0.5.0

Open the chart page →

25,122
escvmschedulerescvmscheduler1.0.71 of 3See more

escvmscheduler escvmscheduler 1.0.7

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
sqlparse@0.4.3
0.5.0

Open the chart page →

4,678
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
sqlparse@0.4.4
0.5.0

Open the chart page →

12,454
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
sqlparse@0.2.4
0.5.0

Open the chart page →

64,489
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
sqlparse@0.4.2
0.5.0

Open the chart page →

1,489
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
sqlparse@0.4.1
0.5.0

Open the chart page →

24,293
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
sqlparse@0.4.2
0.5.0

Open the chart page →

3,064
pgadminhalkeye1.0.01 of 1See more

pgadmin halkeye 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
chorss/docker-pgadmin4:4.115c549cacb8ab
sqlparse@0.2.4
0.5.0

Open the chart page →

2,555

Container images carrying it

69 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.5.0
3
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.5.0
3
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.5.0
2
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.5.0
2
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.5.0
2
alexeyr7/sf-test-app:latestdf0b41fdbd53
sqlparse@0.4.2
0.5.0
1
amancevice/superset:0.28.1c8c04bfe3d66
sqlparse@0.2.4
0.5.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
sqlparse@0.4.4
0.5.0
1
apache/airflow:2.8.1e5560ad0b86e
sqlparse@0.4.4
0.5.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
sqlparse@0.3.0
0.5.0
1
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.5.0
1
buntha/mlflow:2.1.1154542cc3083
sqlparse@0.4.3
0.5.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
sqlparse@0.4.4
0.5.0
1
chorss/docker-pgadmin4:4.115c549cacb8ab
sqlparse@0.2.4
0.5.0
1
codecov/self-hosted-api:24.4.10475cb1c3136
sqlparse@0.4.4
0.5.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
sqlparse@0.4.4
0.5.0
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlparse@0.4.4
0.5.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlparse@0.4.4
0.5.0
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
sqlparse@0.4.4
0.5.0
1
dpage/pgadmin4:8.418cd5711fc9a
sqlparse@0.4.4
0.5.0
1
dpage/pgadmin4:7.537946e4f3e7b
sqlparse@0.4.4
0.5.0
1
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.5.0
1
dpage/pgadmin4:4.22b1f00b8163cf
sqlparse@0.2.4
0.5.0
1
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.5.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
sqlparse@0.2.4
0.5.0
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
sqlparse@0.4.1
0.5.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
sqlparse@0.4.2
0.5.0
1
galaxy/galaxy-init:v18.010267bad550e6
sqlparse@0.1.16
0.5.0
1
gethue/hue:4.11.011b649636e68
sqlparse@0.4.2
0.5.0
1
gethue/hue:4.10.05702b2c37ff9
sqlparse@0.4.1
0.5.0
1
gluufederation/opendj:4.3.0_011a1128b28b95
sqlparse@0.4.2
0.5.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
sqlparse@0.3.1
0.5.0
1
ha33ona/python:test6affdfc644d0
sqlparse@0.4.2
0.5.0
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
sqlparse@0.4.3
0.5.0
1
hhyo/archery:v1.9.11aa41843419e
sqlparse@0.4.3
0.5.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
sqlparse@0.4.1
0.5.0
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
sqlparse@0.4.2
0.5.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
sqlparse@0.4.2
0.5.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
sqlparse@0.4.2
0.5.0
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.5.0
1
linuxserver/babybuddy:1.10.2f7d7c7704249
sqlparse@0.4.2
0.5.0
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
sqlparse@0.4.1
0.5.0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
sqlparse@0.4.3
0.5.0
1
milesmcc/shynet:v0.13.1ba54f7797a6b
sqlparse@0.4.4
0.5.0
1
milesmcc/shynet:v0.12.0e821e31140f7
sqlparse@0.4.2
0.5.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
sqlparse@0.4.4
0.5.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
sqlparse@0.4.2
0.5.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
sqlparse@0.4.4
0.5.0
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
sqlparse@0.4.1
0.5.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
sqlparse@0.4.1
0.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.