StackRadar

CVE-2026-59893

High

Advisory

Published 17 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
149
deployed by those charts
Fix available
1 of 2
affected packages

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 149 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+10 more0.6.0149
sqlparsedeb0.2.4-3no fix listed1
OSV records
GHSA-prg7-hcfm-mfcrUBUNTU-CVE-2026-59893
Also known as
PYSEC-2026-3698

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
sqlparse@0.5.3
0.6.0

Open the chart page →

4,768
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.6.0

Open the chart page →

3,392
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59893.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.6.0

Open the chart page →

7,085

Container images carrying it

149 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
seafileltd/seafile-mc:9.0.97ac833196f60
sqlparse@0.4.2
0.6.0
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
sqlparse@0.5.1
0.6.0
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
sqlparse@0.4.1
0.6.0
1
signalen/backend:2.50.14760256000738
sqlparse@0.5.5
0.6.0
1
sissbruecker/linkding:1.35.00c5dddf0b37c
sqlparse@0.5.1
0.6.0
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
sqlparse@0.5.1
0.6.0
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
sqlparse@0.2.4-3
sqlparse@0.2.4
no fix listed
0.6.0
1
statcan/ckan:2.93921305425b8
sqlparse@0.2.2
0.6.0
1
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
sqlparse@0.4.3
0.6.0
1
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
sqlparse@0.4.3
0.6.0
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
sqlparse@0.4.3
0.6.0
1
taigaio/taiga-back:6.4.29f97323cc150
sqlparse@0.4.1
0.6.0
1
vabene1111/recipes:2.3.50f8d061895e9
sqlparse@0.5.3
0.6.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
sqlparse@0.4.2
0.6.0
1
weblate/weblate:3.11.3-182848df56ecd
sqlparse@0.3.1
0.6.0
1
wger/server:2.6997ead43aabd
sqlparse@0.5.5
0.6.0
1
gcr.io/getindata-images-public/mlflow:latest25d6975951f1
sqlparse@0.5.0
0.6.0
1
ghcr.io/argonix-io/argonix-api:1.0.068e17a8aaa40
sqlparse@0.5.5
0.6.0
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
sqlparse@0.5.3
0.6.0
1
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
sqlparse@0.5.5
0.6.0
1
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
sqlparse@0.5.3
0.6.0
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
sqlparse@0.5.4
0.6.0
1
ghcr.io/getsentry/snuba:26.7.210f8d164109b
sqlparse@0.5.4
0.6.0
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
sqlparse@0.5.5
0.6.0
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
sqlparse@0.5.5
0.6.0
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
sqlparse@0.5.0
0.6.0
1
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
sqlparse@0.5.5
0.6.0
1
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
sqlparse@0.5.5
0.6.0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
sqlparse@0.5.0
0.6.0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
sqlparse@0.5.5
0.6.0
1
ghcr.io/libretime/libretime-api:latesteae026cc8909
sqlparse@0.5.3
0.6.0
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
sqlparse@0.5.3
0.6.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
sqlparse@0.5.0
0.6.0
1
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
sqlparse@0.4.4
0.6.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
sqlparse@0.5.1
0.6.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
sqlparse@0.5.3
0.6.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
sqlparse@0.5.3
0.6.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
sqlparse@0.5.3
0.6.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
sqlparse@0.4.2
0.6.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
sqlparse@0.4.4
0.6.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
sqlparse@0.5.3
0.6.0
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
sqlparse@0.5.5
0.6.0
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
sqlparse@0.5.5
0.6.0
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
sqlparse@0.5.3
0.6.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
sqlparse@0.5.3
0.6.0
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
sqlparse@0.5.3
0.6.0
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
sqlparse@0.5.5
0.6.0
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
sqlparse@0.5.5
0.6.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
sqlparse@0.5.3
0.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.