StackRadar

CVE-2026-54284

High

Advisory

Published 17 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
149
deployed by those charts
Fix available
1 of 2
affected packages

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 149 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+10 more0.6.0149
sqlparsedeb0.2.4-3no fix listed1
OSV records
GHSA-pwgv-4x5q-6m9fUBUNTU-CVE-2026-54284
Also known as
PYSEC-2026-3699

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
sqlparse@0.2.4
0.6.0

Open the chart page →

64,489
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
sqlparse@0.5.3
0.6.0

Open the chart page →

2,183
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
sqlparse@0.4.2
0.6.0

Open the chart page →

1,489
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
sqlparse@0.4.1
0.6.0

Open the chart page →

24,293
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
sqlparse@0.4.2
0.6.0

Open the chart page →

3,064
pgadminhalkeye1.0.01 of 1See more

pgadmin halkeye 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
chorss/docker-pgadmin4:4.115c549cacb8ab
sqlparse@0.2.4
0.6.0

Open the chart page →

2,555
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
sqlparse@0.5.0
0.6.0

Open the chart page →

4,647
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.6.0

Open the chart page →

4,422
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.6.0

Open the chart page →

7,984
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
sqlparse@0.5.5
0.6.0

Open the chart page →

7,633
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
sqlparse@0.5.5
0.6.0

Open the chart page →

10,849
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
sqlparse@0.4.4
0.6.0

Open the chart page →

16,384
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
sqlparse@0.4.1
0.6.0

Open the chart page →

6,501
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
sqlparse@0.4.3
0.6.0

Open the chart page →

2,628
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
sqlparse@0.5.5
0.6.0

Open the chart page →

3,157
pgadmininseefrlab3.2.01 of 1See more

pgadmin inseefrlab 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0

Open the chart page →

398
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
sqlparse@0.3.0
0.6.0

Open the chart page →

3,314
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
sqlparse@0.5.5
0.6.0

Open the chart page →

17,852
ja-shortenerja-shortenerVerified publisher0.1.01 of 2See more

ja-shortener ja-shortener 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
cr0hn/ja-shortener:v0.1.414482d0bc4a1
sqlparse@0.5.3
0.6.0

Open the chart page →

2,089
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
sqlparse@0.4.4
0.6.0

Open the chart page →

2,581
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
sqlparse@0.5.3
0.6.0

Open the chart page →

9,103
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
sqlparse@0.5.5
0.6.0

Open the chart page →

4,568
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
sqlparse@0.4.2
0.6.0

Open the chart page →

16,417
mlflowkelvins0.4.01 of 3See more

mlflow kelvins 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
kelvinsp/mlflow:1.26.1cd33e6db2a59
sqlparse@0.4.2
0.6.0

Open the chart page →

4,156
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
sqlparse@0.5.3
0.6.0

Open the chart page →

8,405
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
sqlparse@0.4.2
0.6.0

Open the chart page →

3,891
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
sqlparse@0.5.1
0.6.0

Open the chart page →

37,942
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
sqlparse@0.5.5
0.6.0

Open the chart page →

2,444
mlflow-servermlflow-server0.3.01 of 1See more

mlflow-server mlflow-server 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
sqlparse@0.4.4
0.6.0

Open the chart page →

3,158
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
sqlparse@0.4.4
0.6.0

Open the chart page →

3,811
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
sqlparse@0.5.3
0.6.0

Open the chart page →

11,950
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.6.0

Open the chart page →

5,456
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
sqlparse@0.5.0
0.6.0

Open the chart page →

4,749
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
sqlparse@0.5.5
0.6.0

Open the chart page →

3,854
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
sqlparse@0.4.2
0.6.0

Open the chart page →

22,084
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-api:latesteae026cc8909
sqlparse@0.5.3
0.6.0

Open the chart page →

11,149
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
sqlparse@0.5.1
0.6.0

Open the chart page →

21,211
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
sqlparse@0.5.3
0.6.0

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
sqlparse@0.5.3
0.6.0

Open the chart page →

4,499
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
sqlparse@0.5.5
0.6.0

Open the chart page →

1,577
safe-stacksafe-global0.1.02 of 9See more

safe-stack safe-global 0.1.0

2 of the 9 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
sqlparse@0.5.5
0.6.0
safeglobal/safe-transaction-service:latest80db836cc5d5
sqlparse@0.5.5
0.6.0

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
safeglobal/safe-transaction-service:latest80db836cc5d5
sqlparse@0.5.5
0.6.0

Open the chart page →

16,620
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
sqlparse@0.4.4
0.6.0

Open the chart page →

10,209
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
sqlparse@0.5.1
0.6.0

Open the chart page →

1,713
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
sqlparse@0.5.5
0.6.0

Open the chart page →

11,636
pgadminsikalabs0.1.01 of 2See more

pgadmin sikalabs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0

Open the chart page →

398
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
sqlparse@0.3.1
0.6.0

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
sqlparse@0.2.4-3
sqlparse@0.2.4
no fix listed
0.6.0

Open the chart page →

30,687
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.6.0

Open the chart page →

2,060
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
sqlparse@0.5.3
0.6.0

Open the chart page →

4,731

Container images carrying it

149 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
galaxy/galaxy-init:v18.010267bad550e6
sqlparse@0.1.16
0.6.0
1
gethue/hue:4.11.011b649636e68
sqlparse@0.4.2
0.6.0
1
gethue/hue:4.10.05702b2c37ff9
sqlparse@0.4.1
0.6.0
1
gethue/hue:latest7d5c1b9f8a79
sqlparse@0.5.0
0.6.0
1
gluufederation/opendj:4.3.0_011a1128b28b95
sqlparse@0.4.2
0.6.0
1
grafana/oncall:v1.16.5499851658393
sqlparse@0.5.3
0.6.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
sqlparse@0.3.1
0.6.0
1
ha33ona/python:test6affdfc644d0
sqlparse@0.4.2
0.6.0
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
sqlparse@0.4.3
0.6.0
1
heartexlabs/label-studio:latestaa461572e8f9
sqlparse@0.5.5
0.6.0
1
hhyo/archery:v1.9.11aa41843419e
sqlparse@0.4.3
0.6.0
1
homeassistant/home-assistant:2026.75a531753cea9
sqlparse@0.5.5
0.6.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
sqlparse@0.4.1
0.6.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
sqlparse@0.5.5
0.6.0
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
sqlparse@0.4.2
0.6.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
sqlparse@0.4.2
0.6.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
sqlparse@0.4.2
0.6.0
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.6.0
1
langgenius/dify-api:1.16.1dcefa5f7c47c
sqlparse@0.5.4
0.6.0
1
langgenius/dify-api:0.6.11fca918260dd6
sqlparse@0.5.0
0.6.0
1
linuxserver/babybuddy:1.10.2f7d7c7704249
sqlparse@0.4.2
0.6.0
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
sqlparse@0.4.1
0.6.0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
sqlparse@0.4.3
0.6.0
1
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
sqlparse@0.5.5
0.6.0
1
maponyacharles/sceptreai:api-0.1.127b37b092130a
sqlparse@0.5.5
0.6.0
1
mathesar/mathesar:0.12.0091757cb01fe
sqlparse@0.5.5
0.6.0
1
milesmcc/shynet:v0.13.1ba54f7797a6b
sqlparse@0.4.4
0.6.0
1
milesmcc/shynet:v0.12.0e821e31140f7
sqlparse@0.4.2
0.6.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
sqlparse@0.4.4
0.6.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
sqlparse@0.4.2
0.6.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
sqlparse@0.5.0
0.6.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
sqlparse@0.5.5
0.6.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
sqlparse@0.4.4
0.6.0
1
opencsghq/label-studio:v2.5.047e22aa71870
sqlparse@0.5.0
0.6.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
sqlparse@0.5.0
0.6.0
1
opennode/waldur-mastermind:8.1.24c82b15d9042
sqlparse@0.5.5
0.6.0
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
sqlparse@0.4.1
0.6.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
sqlparse@0.4.1
0.6.0
1
openzaak/open-notificaties:1.3.02e65313b9b10
sqlparse@0.4.2
0.6.0
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
sqlparse@0.4.2
0.6.0
1
pretix/standalone:2026.7.05df3b7aa852e
sqlparse@0.5.5
0.6.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
sqlparse@0.5.5
0.6.0
1
psono/psono-server:5.0.03b974b43ea03
sqlparse@0.5.0
0.6.0
1
recordsansible/ara-api:latest9dfd6e18f474
sqlparse@0.5.5
0.6.0
1
redash/redash:25.8.000d813437db5
sqlparse@0.5.0
0.6.0
1
redash/redash:10.0.0.b503639392753c0376
sqlparse@0.3.0
0.6.0
1
redash/redash:26.3.0c5c9148f5c38
sqlparse@0.5.0
0.6.0
1
redislabs/redisinsight:1.14.0b03ab1426d0d
sqlparse@0.4.4
0.6.0
1
seafileltd/seafile-mc:9.0.106693911bcc40
sqlparse@0.4.3
0.6.0
1
seafileltd/seafile-mc:10.0.170628f29c663
sqlparse@0.4.3
0.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.