StackRadar

CVE-2026-59893

High

Advisory

Published 17 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
149
deployed by those charts
Fix available
1 of 2
affected packages

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 149 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+10 more0.6.0149
sqlparsedeb0.2.4-3no fix listed1
OSV records
GHSA-prg7-hcfm-mfcrUBUNTU-CVE-2026-59893
Also known as
PYSEC-2026-3698

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
sqlparse@0.5.3
0.6.0

Open the chart page →

6,873
open-notificatiesopen-zaak0.7.01 of 4See more

open-notificaties open-zaak 0.7.0

1 of the 4 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
openzaak/open-notificaties:1.3.02e65313b9b10
sqlparse@0.4.2
0.6.0

Open the chart page →

2,850
home-assistantpree-helm-chartsVerified publisher1.80.01 of 1See more

home-assistant pree-helm-charts 1.80.0

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
sqlparse@0.5.5
0.6.0

Open the chart page →

2,133
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
sqlparse@0.5.5
0.6.0

Open the chart page →

8,158
sceptresceptreai0.1.122 of 5See more

sceptre sceptreai 0.1.12

2 of the 5 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
sqlparse@0.5.5
0.6.0
maponyacharles/sceptreai:api-0.1.127b37b092130a
sqlparse@0.5.5
0.6.0

Open the chart page →

4,369
sentry-k8ssentry-k8sVerified publisher1.4.12 of 11See more

sentry-k8s sentry-k8s 1.4.1

2 of the 11 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
sqlparse@0.5.4
0.6.0
ghcr.io/getsentry/snuba:26.7.210f8d164109b
sqlparse@0.5.4
0.6.0

Open the chart page →

16,449
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
sqlparse@0.4.3
0.6.0

Open the chart page →

2,236
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
sqlparse@0.2.2
0.6.0

Open the chart page →

24,930
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
sqlparse@0.5.3
0.6.0

Open the chart page →

9,148
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
sqlparse@0.5.0
0.6.0

Open the chart page →

2,233
waldurwaldur-chartsVerified publisher8.1.21 of 3See more

waldur waldur-charts 8.1.2

1 of the 3 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
opennode/waldur-mastermind:8.1.24c82b15d9042
sqlparse@0.5.5
0.6.0

Open the chart page →

4,839
qleverzazukoVerified publisher0.7.01 of 2See more

qlever zazuko 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
sqlparse@0.5.5
0.6.0

Open the chart page →

2,900
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
sqlparse@0.5.5
0.6.0

Open the chart page →

7,239
ddosifyanteonVerified publisher1.7.53 of 13See more

ddosify anteon 1.7.5

3 of the 13 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlparse@0.4.4
0.6.0
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlparse@0.4.4
0.6.0
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
sqlparse@0.4.4
0.6.0

Open the chart page →

25,669
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
sqlparse@0.5.4
0.6.0

Open the chart page →

1,565
argonix-apiargonix0.2.01 of 4See more

argonix-api argonix 0.2.0

1 of the 4 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.068e17a8aaa40
sqlparse@0.5.5
0.6.0

Open the chart page →

4,923
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.6.0

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.6.0

Open the chart page →

2,418
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
sqlparse@0.4.1
0.6.0
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
sqlparse@0.4.1
0.6.0

Open the chart page →

22,568
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.6.0

Open the chart page →

10,061
shynetatrox0.1.11 of 1See more

shynet atrox 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.12.0e821e31140f7
sqlparse@0.4.2
0.6.0

Open the chart page →

5,507
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
sqlparse@0.4.1
0.6.0

Open the chart page →

22,891
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
sqlparse@0.5.0
0.6.0

Open the chart page →

10,145
bdbablackduck2026.6.31 of 9See more

bdba blackduck 2026.6.3

1 of the 9 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
blackducksoftware/bdba-frontend:2026.6.3b10eaea94fd3
sqlparse@0.5.5
0.6.0

Open the chart page →

9,521
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
sqlparse@0.4.4
0.6.0

Open the chart page →

2,507
opencvecfi20170.1.22 of 7See more

opencve cfi2017 0.1.2

2 of the 7 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
sqlparse@0.5.3
0.6.0
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
sqlparse@0.5.5
0.6.0

Open the chart page →

15,371
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
sqlparse@0.2.4
0.6.0

Open the chart page →

5,060
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.6.0

Open the chart page →

12,457
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.6.0

Open the chart page →

12,131
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.6.0

Open the chart page →

11,592
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
sqlparse@0.5.5
0.6.0

Open the chart page →

4,601
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
sqlparse@0.4.2
0.6.0

Open the chart page →

16,069
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
sqlparse@0.1.16
0.6.0

Open the chart page →

70,895
authentikcluster-deploy0.2.01 of 1See more

authentik cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
sqlparse@0.5.5
0.6.0

Open the chart page →

2,481
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.4.0b4e849fcf94a
sqlparse@0.5.0
0.6.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
sqlparse@0.4.4
0.6.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
sqlparse@0.5.0
0.6.0

Open the chart page →

6,632
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
sqlparse@0.5.0
0.6.0

Open the chart page →

5,062
datagrokdatagrok1.0.31 of 7See more

datagrok datagrok 1.0.3

1 of the 7 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
datagrok/grok_spawner:latest8c2d48c1545c
sqlparse@0.5.5
0.6.0

Open the chart page →

2,328
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
sqlparse@0.5.1
0.6.0

Open the chart page →

6,075
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.6.0

Open the chart page →

4,422
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
sqlparse@0.4.3
0.6.0

Open the chart page →

14,856
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
alexeyr7/sf-test-app:latestdf0b41fdbd53
sqlparse@0.4.2
0.6.0

Open the chart page →

2,548
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
sqlparse@0.5.5
0.6.0

Open the chart page →

7,459
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
sqlparse@0.4.4
0.6.0
codecov/self-hosted-worker:24.4.1837f546b479b
sqlparse@0.4.4
0.6.0

Open the chart page →

24,917
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
sqlparse@0.5.5
0.6.0

Open the chart page →

2,158
pgadmin4eks-storageclass0.1.01 of 2See more

pgadmin4 eks-storageclass 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0

Open the chart page →

398
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
sqlparse@0.4.3
0.6.0

Open the chart page →

25,122
escvmschedulerescvmscheduler1.0.71 of 3See more

escvmscheduler escvmscheduler 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
sqlparse@0.4.3
0.6.0

Open the chart page →

4,678
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
sqlparse@0.4.4
0.6.0

Open the chart page →

12,454

Container images carrying it

149 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
galaxy/galaxy-init:v18.010267bad550e6
sqlparse@0.1.16
0.6.0
1
gethue/hue:4.11.011b649636e68
sqlparse@0.4.2
0.6.0
1
gethue/hue:4.10.05702b2c37ff9
sqlparse@0.4.1
0.6.0
1
gethue/hue:latest7d5c1b9f8a79
sqlparse@0.5.0
0.6.0
1
gluufederation/opendj:4.3.0_011a1128b28b95
sqlparse@0.4.2
0.6.0
1
grafana/oncall:v1.16.5499851658393
sqlparse@0.5.3
0.6.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
sqlparse@0.3.1
0.6.0
1
ha33ona/python:test6affdfc644d0
sqlparse@0.4.2
0.6.0
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
sqlparse@0.4.3
0.6.0
1
heartexlabs/label-studio:latestaa461572e8f9
sqlparse@0.5.5
0.6.0
1
hhyo/archery:v1.9.11aa41843419e
sqlparse@0.4.3
0.6.0
1
homeassistant/home-assistant:2026.75a531753cea9
sqlparse@0.5.5
0.6.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
sqlparse@0.4.1
0.6.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
sqlparse@0.5.5
0.6.0
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
sqlparse@0.4.2
0.6.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
sqlparse@0.4.2
0.6.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
sqlparse@0.4.2
0.6.0
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.6.0
1
langgenius/dify-api:1.16.1dcefa5f7c47c
sqlparse@0.5.4
0.6.0
1
langgenius/dify-api:0.6.11fca918260dd6
sqlparse@0.5.0
0.6.0
1
linuxserver/babybuddy:1.10.2f7d7c7704249
sqlparse@0.4.2
0.6.0
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
sqlparse@0.4.1
0.6.0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
sqlparse@0.4.3
0.6.0
1
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
sqlparse@0.5.5
0.6.0
1
maponyacharles/sceptreai:api-0.1.127b37b092130a
sqlparse@0.5.5
0.6.0
1
mathesar/mathesar:0.12.0091757cb01fe
sqlparse@0.5.5
0.6.0
1
milesmcc/shynet:v0.13.1ba54f7797a6b
sqlparse@0.4.4
0.6.0
1
milesmcc/shynet:v0.12.0e821e31140f7
sqlparse@0.4.2
0.6.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
sqlparse@0.4.4
0.6.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
sqlparse@0.4.2
0.6.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
sqlparse@0.5.0
0.6.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
sqlparse@0.5.5
0.6.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
sqlparse@0.4.4
0.6.0
1
opencsghq/label-studio:v2.5.047e22aa71870
sqlparse@0.5.0
0.6.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
sqlparse@0.5.0
0.6.0
1
opennode/waldur-mastermind:8.1.24c82b15d9042
sqlparse@0.5.5
0.6.0
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
sqlparse@0.4.1
0.6.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
sqlparse@0.4.1
0.6.0
1
openzaak/open-notificaties:1.3.02e65313b9b10
sqlparse@0.4.2
0.6.0
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
sqlparse@0.4.2
0.6.0
1
pretix/standalone:2026.7.05df3b7aa852e
sqlparse@0.5.5
0.6.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
sqlparse@0.5.5
0.6.0
1
psono/psono-server:5.0.03b974b43ea03
sqlparse@0.5.0
0.6.0
1
recordsansible/ara-api:latest9dfd6e18f474
sqlparse@0.5.5
0.6.0
1
redash/redash:25.8.000d813437db5
sqlparse@0.5.0
0.6.0
1
redash/redash:10.0.0.b503639392753c0376
sqlparse@0.3.0
0.6.0
1
redash/redash:26.3.0c5c9148f5c38
sqlparse@0.5.0
0.6.0
1
redislabs/redisinsight:1.14.0b03ab1426d0d
sqlparse@0.4.4
0.6.0
1
seafileltd/seafile-mc:9.0.106693911bcc40
sqlparse@0.4.3
0.6.0
1
seafileltd/seafile-mc:10.0.170628f29c663
sqlparse@0.4.3
0.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.