StackRadar

CVE-2026-71491

High

Advisory

Published 17 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
149
deployed by those charts
Fix available
1 of 2
affected packages

sqlparse: Quadratic O(n²) DoS in group_comments

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 149 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+10 more0.6.0149
sqlparsedeb0.2.4-3no fix listed1
OSV records
GHSA-f2ff-p2ww-7p4pUBUNTU-CVE-2026-71491
Also known as
PYSEC-2026-3697

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
sqlparse@0.5.3
0.6.0

Open the chart page →

4,768
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.6.0

Open the chart page →

3,392
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.6.0

Open the chart page →

7,085

Container images carrying it

149 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
galaxy/galaxy-init:v18.010267bad550e6
sqlparse@0.1.16
0.6.0
1
gethue/hue:4.11.011b649636e68
sqlparse@0.4.2
0.6.0
1
gethue/hue:4.10.05702b2c37ff9
sqlparse@0.4.1
0.6.0
1
gethue/hue:latest7d5c1b9f8a79
sqlparse@0.5.0
0.6.0
1
gluufederation/opendj:4.3.0_011a1128b28b95
sqlparse@0.4.2
0.6.0
1
grafana/oncall:v1.16.5499851658393
sqlparse@0.5.3
0.6.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
sqlparse@0.3.1
0.6.0
1
ha33ona/python:test6affdfc644d0
sqlparse@0.4.2
0.6.0
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
sqlparse@0.4.3
0.6.0
1
heartexlabs/label-studio:latestaa461572e8f9
sqlparse@0.5.5
0.6.0
1
hhyo/archery:v1.9.11aa41843419e
sqlparse@0.4.3
0.6.0
1
homeassistant/home-assistant:2026.75a531753cea9
sqlparse@0.5.5
0.6.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
sqlparse@0.4.1
0.6.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
sqlparse@0.5.5
0.6.0
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
sqlparse@0.4.2
0.6.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
sqlparse@0.4.2
0.6.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
sqlparse@0.4.2
0.6.0
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.6.0
1
langgenius/dify-api:1.16.1dcefa5f7c47c
sqlparse@0.5.4
0.6.0
1
langgenius/dify-api:0.6.11fca918260dd6
sqlparse@0.5.0
0.6.0
1
linuxserver/babybuddy:1.10.2f7d7c7704249
sqlparse@0.4.2
0.6.0
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
sqlparse@0.4.1
0.6.0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
sqlparse@0.4.3
0.6.0
1
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
sqlparse@0.5.5
0.6.0
1
maponyacharles/sceptreai:api-0.1.127b37b092130a
sqlparse@0.5.5
0.6.0
1
mathesar/mathesar:0.12.0091757cb01fe
sqlparse@0.5.5
0.6.0
1
milesmcc/shynet:v0.13.1ba54f7797a6b
sqlparse@0.4.4
0.6.0
1
milesmcc/shynet:v0.12.0e821e31140f7
sqlparse@0.4.2
0.6.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
sqlparse@0.4.4
0.6.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
sqlparse@0.4.2
0.6.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
sqlparse@0.5.0
0.6.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
sqlparse@0.5.5
0.6.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
sqlparse@0.4.4
0.6.0
1
opencsghq/label-studio:v2.5.047e22aa71870
sqlparse@0.5.0
0.6.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
sqlparse@0.5.0
0.6.0
1
opennode/waldur-mastermind:8.1.24c82b15d9042
sqlparse@0.5.5
0.6.0
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
sqlparse@0.4.1
0.6.0
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
sqlparse@0.4.1
0.6.0
1
openzaak/open-notificaties:1.3.02e65313b9b10
sqlparse@0.4.2
0.6.0
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
sqlparse@0.4.2
0.6.0
1
pretix/standalone:2026.7.05df3b7aa852e
sqlparse@0.5.5
0.6.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
sqlparse@0.5.5
0.6.0
1
psono/psono-server:5.0.03b974b43ea03
sqlparse@0.5.0
0.6.0
1
recordsansible/ara-api:latest9dfd6e18f474
sqlparse@0.5.5
0.6.0
1
redash/redash:25.8.000d813437db5
sqlparse@0.5.0
0.6.0
1
redash/redash:10.0.0.b503639392753c0376
sqlparse@0.3.0
0.6.0
1
redash/redash:26.3.0c5c9148f5c38
sqlparse@0.5.0
0.6.0
1
redislabs/redisinsight:1.14.0b03ab1426d0d
sqlparse@0.4.4
0.6.0
1
seafileltd/seafile-mc:9.0.106693911bcc40
sqlparse@0.4.3
0.6.0
1
seafileltd/seafile-mc:10.0.170628f29c663
sqlparse@0.4.3
0.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.