StackRadar

CVE-2026-54284

High

Advisory

Published 17 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
149
deployed by those charts
Fix available
1 of 2
affected packages

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 149 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+10 more0.6.0149
sqlparsedeb0.2.4-3no fix listed1
OSV records
GHSA-pwgv-4x5q-6m9fUBUNTU-CVE-2026-54284
Also known as
PYSEC-2026-3699

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
sqlparse@0.5.3
0.6.0

Open the chart page →

4,768
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.6.0

Open the chart page →

3,392
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54284.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.6.0

Open the chart page →

7,085

Container images carrying it

149 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dpage/pgadmin4:9.17:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0
5
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.6.0
3
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.6.0
3
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.6.0
2
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.6.0
2
safeglobal/safe-config-service:latest09a5e495c219
sqlparse@0.5.5
0.6.0
2
safeglobal/safe-transaction-service:latest80db836cc5d5
sqlparse@0.5.5
0.6.0
2
taigaio/taiga-back:latest4beed8f62c9f
sqlparse@0.5.3
0.6.0
2
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.6.0
2
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
sqlparse@0.5.5
0.6.0
2
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
sqlparse@0.5.5
0.6.0
2
alexeyr7/sf-test-app:latestdf0b41fdbd53
sqlparse@0.4.2
0.6.0
1
amancevice/superset:0.28.1c8c04bfe3d66
sqlparse@0.2.4
0.6.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
sqlparse@0.4.4
0.6.0
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
sqlparse@0.5.1
0.6.0
1
apache/airflow:2.8.1e5560ad0b86e
sqlparse@0.4.4
0.6.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
sqlparse@0.3.0
0.6.0
1
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.6.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
sqlparse@0.5.3
0.6.0
1
archivebox/archivebox:0.7.41a5a37331091
sqlparse@0.5.5
0.6.0
1
baserow/backend:2.3.37c00549b3a6f
sqlparse@0.5.5
0.6.0
1
baserow/backend:1.31.1e0b3c8130b91
sqlparse@0.5.0
0.6.0
1
baserow/baserow:1.30.1df0c42eb67e8
sqlparse@0.5.0
0.6.0
1
blackducksoftware/bdba-frontend:2026.6.3b10eaea94fd3
sqlparse@0.5.5
0.6.0
1
buntha/mlflow:2.1.1154542cc3083
sqlparse@0.4.3
0.6.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
sqlparse@0.4.4
0.6.0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
sqlparse@0.5.5
0.6.0
1
chorss/docker-pgadmin4:4.115c549cacb8ab
sqlparse@0.2.4
0.6.0
1
codecov/self-hosted-api:24.4.10475cb1c3136
sqlparse@0.4.4
0.6.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
sqlparse@0.4.4
0.6.0
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
sqlparse@0.5.3
0.6.0
1
datagrok/grok_spawner:latest8c2d48c1545c
sqlparse@0.5.5
0.6.0
1
datamate/seafile-professional:11.0.202dd66b722464
sqlparse@0.5.3
0.6.0
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
sqlparse@0.5.1
0.6.0
1
ddosify/selfhosted_backend:3.2.93c11e3182652
sqlparse@0.5.0
0.6.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
sqlparse@0.5.0
0.6.0
1
dpage/pgadmin4:8.418cd5711fc9a
sqlparse@0.4.4
0.6.0
1
dpage/pgadmin4:7.537946e4f3e7b
sqlparse@0.4.4
0.6.0
1
dpage/pgadmin4:9.11.050700ac17936
sqlparse@0.5.4
0.6.0
1
dpage/pgadmin4:9.252cb72a9e3da
sqlparse@0.5.3
0.6.0
1
dpage/pgadmin4:8.13561c1f8f99f2
sqlparse@0.5.1
0.6.0
1
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.6.0
1
dpage/pgadmin4:4.22b1f00b8163cf
sqlparse@0.2.4
0.6.0
1
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.6.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
sqlparse@0.2.4
0.6.0
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
sqlparse@0.4.1
0.6.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
sqlparse@0.4.2
0.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.