StackRadar

CVE-2024-4340

High

Advisory

Published 15 Apr 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.032
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
70
of 17,781 indexed, latest versions
Container images
69
deployed by those charts
Fix available
1 of 1
affected package

sqlparse parsing heavily nested list leads to Denial of Service

Carried by container images the latest versions of 70 of 17,781 indexed charts deploy, on 69 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+5 more0.5.069
OSV records
GHSA-2m57-hf25-phgg
Also known as
PYSEC-2026-1940

Charts affected

70 by stars
ChartLatestAffected imagesRadar Score
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.5.0

Open the chart page →

4,422
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.5.0

Open the chart page →

7,984
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
sqlparse@0.4.4
0.5.0

Open the chart page →

16,384
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
sqlparse@0.4.1
0.5.0

Open the chart page →

6,501
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
sqlparse@0.4.3
0.5.0

Open the chart page →

2,628
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
sqlparse@0.3.0
0.5.0

Open the chart page →

3,314
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
sqlparse@0.4.4
0.5.0

Open the chart page →

2,581
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
sqlparse@0.4.2
0.5.0

Open the chart page →

16,417
mlflowkelvins0.4.01 of 3See more

mlflow kelvins 0.4.0

1 of the 3 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
kelvinsp/mlflow:1.26.1cd33e6db2a59
sqlparse@0.4.2
0.5.0

Open the chart page →

4,156
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
sqlparse@0.4.2
0.5.0

Open the chart page →

3,891
mlflow-servermlflow-server0.3.01 of 1See more

mlflow-server mlflow-server 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
sqlparse@0.4.4
0.5.0

Open the chart page →

3,158
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
sqlparse@0.4.4
0.5.0

Open the chart page →

3,811
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.5.0

Open the chart page →

5,456
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
sqlparse@0.4.2
0.5.0

Open the chart page →

22,084
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
sqlparse@0.4.4
0.5.0

Open the chart page →

10,209
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
sqlparse@0.3.1
0.5.0

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
sqlparse@0.2.4
0.5.0

Open the chart page →

30,687
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.5.0

Open the chart page →

2,060
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.5.0

Open the chart page →

3,392
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-4340.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.5.0

Open the chart page →

7,085

Container images carrying it

69 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.5.0
3
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.5.0
3
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.5.0
2
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.5.0
2
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.5.0
2
alexeyr7/sf-test-app:latestdf0b41fdbd53
sqlparse@0.4.2
0.5.0
1
amancevice/superset:0.28.1c8c04bfe3d66
sqlparse@0.2.4
0.5.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
sqlparse@0.4.4
0.5.0
1
apache/airflow:2.8.1e5560ad0b86e
sqlparse@0.4.4
0.5.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
sqlparse@0.3.0
0.5.0
1
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.5.0
1
buntha/mlflow:2.1.1154542cc3083
sqlparse@0.4.3
0.5.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
sqlparse@0.4.4
0.5.0
1
chorss/docker-pgadmin4:4.115c549cacb8ab
sqlparse@0.2.4
0.5.0
1
codecov/self-hosted-api:24.4.10475cb1c3136
sqlparse@0.4.4
0.5.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
sqlparse@0.4.4
0.5.0
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlparse@0.4.4
0.5.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlparse@0.4.4
0.5.0
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
sqlparse@0.4.4
0.5.0
1
dpage/pgadmin4:8.418cd5711fc9a
sqlparse@0.4.4
0.5.0
1
dpage/pgadmin4:7.537946e4f3e7b
sqlparse@0.4.4
0.5.0
1
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.5.0
1
dpage/pgadmin4:4.22b1f00b8163cf
sqlparse@0.2.4
0.5.0
1
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.5.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
sqlparse@0.2.4
0.5.0
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
sqlparse@0.4.1
0.5.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
sqlparse@0.4.2
0.5.0
1
galaxy/galaxy-init:v18.010267bad550e6
sqlparse@0.1.16
0.5.0
1
gethue/hue:4.11.011b649636e68
sqlparse@0.4.2
0.5.0
1
gethue/hue:4.10.05702b2c37ff9
sqlparse@0.4.1
0.5.0
1
gluufederation/opendj:4.3.0_011a1128b28b95
sqlparse@0.4.2
0.5.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
sqlparse@0.3.1
0.5.0
1
ha33ona/python:test6affdfc644d0
sqlparse@0.4.2
0.5.0
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
sqlparse@0.4.3
0.5.0
1
hhyo/archery:v1.9.11aa41843419e
sqlparse@0.4.3
0.5.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
sqlparse@0.4.1
0.5.0
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
sqlparse@0.4.2
0.5.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
sqlparse@0.4.2
0.5.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
sqlparse@0.4.2
0.5.0
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.5.0
1
linuxserver/babybuddy:1.10.2f7d7c7704249
sqlparse@0.4.2
0.5.0
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
sqlparse@0.4.1
0.5.0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
sqlparse@0.4.3
0.5.0
1
milesmcc/shynet:v0.13.1ba54f7797a6b
sqlparse@0.4.4
0.5.0
1
milesmcc/shynet:v0.12.0e821e31140f7
sqlparse@0.4.2
0.5.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
sqlparse@0.4.4
0.5.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
sqlparse@0.4.2
0.5.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
sqlparse@0.4.4
0.5.0
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
sqlparse@0.4.1
0.5.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
sqlparse@0.4.1
0.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.