StackRadar

CVE-2024-4340

High

Advisory

Published 15 Apr 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.032
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
70
of 17,781 indexed, latest versions
Container images
69
deployed by those charts
Fix available
1 of 1
affected package

sqlparse parsing heavily nested list leads to Denial of Service

Carried by container images the latest versions of 70 of 17,781 indexed charts deploy, on 69 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+5 more0.5.069
OSV records
GHSA-2m57-hf25-phgg
Also known as
PYSEC-2026-1940

Charts affected

70 by stars
ChartLatestAffected imagesRadar Score
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.5.0

Open the chart page →

4,422
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.5.0

Open the chart page →

7,984
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
sqlparse@0.4.4
0.5.0

Open the chart page →

16,384
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
sqlparse@0.4.1
0.5.0

Open the chart page →

6,501
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
sqlparse@0.4.3
0.5.0

Open the chart page →

2,628
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
sqlparse@0.3.0
0.5.0

Open the chart page →

3,314
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
sqlparse@0.4.4
0.5.0

Open the chart page →

2,581
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
sqlparse@0.4.2
0.5.0

Open the chart page →

16,417
mlflowkelvins0.4.01 of 3See more

mlflow kelvins 0.4.0

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
kelvinsp/mlflow:1.26.1cd33e6db2a59
sqlparse@0.4.2
0.5.0

Open the chart page →

4,156
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
sqlparse@0.4.2
0.5.0

Open the chart page →

3,891
mlflow-servermlflow-server0.3.01 of 1See more

mlflow-server mlflow-server 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
sqlparse@0.4.4
0.5.0

Open the chart page →

3,158
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
sqlparse@0.4.4
0.5.0

Open the chart page →

3,811
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.5.0

Open the chart page →

5,456
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
sqlparse@0.4.2
0.5.0

Open the chart page →

22,084
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
sqlparse@0.4.4
0.5.0

Open the chart page →

10,209
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
sqlparse@0.3.1
0.5.0

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
sqlparse@0.2.4
0.5.0

Open the chart page →

30,687
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.5.0

Open the chart page →

2,060
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.5.0

Open the chart page →

3,392
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.5.0

Open the chart page →

7,085

Container images carrying it

69 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
openzaak/open-notificaties:1.3.02e65313b9b10
sqlparse@0.4.2
0.5.0
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
sqlparse@0.4.2
0.5.0
1
redash/redash:10.0.0.b503639392753c0376
sqlparse@0.3.0
0.5.0
1
redislabs/redisinsight:1.14.0b03ab1426d0d
sqlparse@0.4.4
0.5.0
1
seafileltd/seafile-mc:9.0.106693911bcc40
sqlparse@0.4.3
0.5.0
1
seafileltd/seafile-mc:10.0.170628f29c663
sqlparse@0.4.3
0.5.0
1
seafileltd/seafile-mc:9.0.97ac833196f60
sqlparse@0.4.2
0.5.0
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
sqlparse@0.4.1
0.5.0
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
sqlparse@0.2.4
0.5.0
1
statcan/ckan:2.93921305425b8
sqlparse@0.2.2
0.5.0
1
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
sqlparse@0.4.3
0.5.0
1
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
sqlparse@0.4.3
0.5.0
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
sqlparse@0.4.3
0.5.0
1
taigaio/taiga-back:6.4.29f97323cc150
sqlparse@0.4.1
0.5.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
sqlparse@0.4.2
0.5.0
1
weblate/weblate:3.11.3-182848df56ecd
sqlparse@0.3.1
0.5.0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
sqlparse@0.4.4
0.5.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
sqlparse@0.4.2
0.5.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
sqlparse@0.4.4
0.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.