StackRadar

CVE-2026-71491

High

Advisory

Published 17 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
149
deployed by those charts
Fix available
1 of 2
affected packages

sqlparse: Quadratic O(n²) DoS in group_comments

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 149 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+10 more0.6.0149
sqlparsedeb0.2.4-3no fix listed1
OSV records
GHSA-f2ff-p2ww-7p4pUBUNTU-CVE-2026-71491
Also known as
PYSEC-2026-3697

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
sqlparse@0.2.4
0.6.0

Open the chart page →

64,489
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
sqlparse@0.5.3
0.6.0

Open the chart page →

2,183
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
sqlparse@0.4.2
0.6.0

Open the chart page →

1,489
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
sqlparse@0.4.1
0.6.0

Open the chart page →

24,293
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
sqlparse@0.4.2
0.6.0

Open the chart page →

3,064
pgadminhalkeye1.0.01 of 1See more

pgadmin halkeye 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
chorss/docker-pgadmin4:4.115c549cacb8ab
sqlparse@0.2.4
0.6.0

Open the chart page →

2,555
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
sqlparse@0.5.0
0.6.0

Open the chart page →

4,647
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.6.0

Open the chart page →

4,422
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.6.0

Open the chart page →

7,984
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
sqlparse@0.5.5
0.6.0

Open the chart page →

7,633
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
sqlparse@0.5.5
0.6.0

Open the chart page →

10,849
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
sqlparse@0.4.4
0.6.0

Open the chart page →

16,384
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
sqlparse@0.4.1
0.6.0

Open the chart page →

6,501
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
sqlparse@0.4.3
0.6.0

Open the chart page →

2,628
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
sqlparse@0.5.5
0.6.0

Open the chart page →

3,157
pgadmininseefrlab3.2.01 of 1See more

pgadmin inseefrlab 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0

Open the chart page →

398
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
sqlparse@0.3.0
0.6.0

Open the chart page →

3,314
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
sqlparse@0.5.5
0.6.0

Open the chart page →

17,852
ja-shortenerja-shortenerVerified publisher0.1.01 of 2See more

ja-shortener ja-shortener 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
cr0hn/ja-shortener:v0.1.414482d0bc4a1
sqlparse@0.5.3
0.6.0

Open the chart page →

2,089
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
sqlparse@0.4.4
0.6.0

Open the chart page →

2,581
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
sqlparse@0.5.3
0.6.0

Open the chart page →

9,103
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
sqlparse@0.5.5
0.6.0

Open the chart page →

4,568
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
sqlparse@0.4.2
0.6.0

Open the chart page →

16,417
mlflowkelvins0.4.01 of 3See more

mlflow kelvins 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
kelvinsp/mlflow:1.26.1cd33e6db2a59
sqlparse@0.4.2
0.6.0

Open the chart page →

4,156
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
sqlparse@0.5.3
0.6.0

Open the chart page →

8,405
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
sqlparse@0.4.2
0.6.0

Open the chart page →

3,891
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
sqlparse@0.5.1
0.6.0

Open the chart page →

37,942
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
sqlparse@0.5.5
0.6.0

Open the chart page →

2,444
mlflow-servermlflow-server0.3.01 of 1See more

mlflow-server mlflow-server 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/mlops-for-all/mlflow-tracking-server:3.8-1.30.1-v1.0.0d30e631684c3
sqlparse@0.4.4
0.6.0

Open the chart page →

3,158
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
sqlparse@0.4.4
0.6.0

Open the chart page →

3,811
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
sqlparse@0.5.3
0.6.0

Open the chart page →

11,950
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.6.0

Open the chart page →

5,456
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
sqlparse@0.5.0
0.6.0

Open the chart page →

4,749
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
sqlparse@0.5.5
0.6.0

Open the chart page →

3,854
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
sqlparse@0.4.2
0.6.0

Open the chart page →

22,084
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-api:latesteae026cc8909
sqlparse@0.5.3
0.6.0

Open the chart page →

11,149
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
sqlparse@0.5.1
0.6.0

Open the chart page →

21,211
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
sqlparse@0.5.3
0.6.0

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
sqlparse@0.5.3
0.6.0

Open the chart page →

4,499
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
sqlparse@0.5.5
0.6.0

Open the chart page →

1,577
safe-stacksafe-global0.1.02 of 9See more

safe-stack safe-global 0.1.0

2 of the 9 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
sqlparse@0.5.5
0.6.0
safeglobal/safe-transaction-service:latest80db836cc5d5
sqlparse@0.5.5
0.6.0

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
safeglobal/safe-transaction-service:latest80db836cc5d5
sqlparse@0.5.5
0.6.0

Open the chart page →

16,620
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
sqlparse@0.4.4
0.6.0

Open the chart page →

10,209
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
sqlparse@0.5.1
0.6.0

Open the chart page →

1,713
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
sqlparse@0.5.5
0.6.0

Open the chart page →

11,636
pgadminsikalabs0.1.01 of 2See more

pgadmin sikalabs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0

Open the chart page →

398
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
sqlparse@0.3.1
0.6.0

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
sqlparse@0.2.4-3
sqlparse@0.2.4
no fix listed
0.6.0

Open the chart page →

30,687
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.6.0

Open the chart page →

2,060
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-71491.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
sqlparse@0.5.3
0.6.0

Open the chart page →

4,731

Container images carrying it

149 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dpage/pgadmin4:9.17:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0
5
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.6.0
3
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.6.0
3
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.6.0
2
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.6.0
2
safeglobal/safe-config-service:latest09a5e495c219
sqlparse@0.5.5
0.6.0
2
safeglobal/safe-transaction-service:latest80db836cc5d5
sqlparse@0.5.5
0.6.0
2
taigaio/taiga-back:latest4beed8f62c9f
sqlparse@0.5.3
0.6.0
2
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.6.0
2
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
sqlparse@0.5.5
0.6.0
2
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
sqlparse@0.5.5
0.6.0
2
alexeyr7/sf-test-app:latestdf0b41fdbd53
sqlparse@0.4.2
0.6.0
1
amancevice/superset:0.28.1c8c04bfe3d66
sqlparse@0.2.4
0.6.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
sqlparse@0.4.4
0.6.0
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
sqlparse@0.5.1
0.6.0
1
apache/airflow:2.8.1e5560ad0b86e
sqlparse@0.4.4
0.6.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
sqlparse@0.3.0
0.6.0
1
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.6.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
sqlparse@0.5.3
0.6.0
1
archivebox/archivebox:0.7.41a5a37331091
sqlparse@0.5.5
0.6.0
1
baserow/backend:2.3.37c00549b3a6f
sqlparse@0.5.5
0.6.0
1
baserow/backend:1.31.1e0b3c8130b91
sqlparse@0.5.0
0.6.0
1
baserow/baserow:1.30.1df0c42eb67e8
sqlparse@0.5.0
0.6.0
1
blackducksoftware/bdba-frontend:2026.6.3b10eaea94fd3
sqlparse@0.5.5
0.6.0
1
buntha/mlflow:2.1.1154542cc3083
sqlparse@0.4.3
0.6.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
sqlparse@0.4.4
0.6.0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
sqlparse@0.5.5
0.6.0
1
chorss/docker-pgadmin4:4.115c549cacb8ab
sqlparse@0.2.4
0.6.0
1
codecov/self-hosted-api:24.4.10475cb1c3136
sqlparse@0.4.4
0.6.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
sqlparse@0.4.4
0.6.0
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
sqlparse@0.5.3
0.6.0
1
datagrok/grok_spawner:latest8c2d48c1545c
sqlparse@0.5.5
0.6.0
1
datamate/seafile-professional:11.0.202dd66b722464
sqlparse@0.5.3
0.6.0
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
sqlparse@0.5.1
0.6.0
1
ddosify/selfhosted_backend:3.2.93c11e3182652
sqlparse@0.5.0
0.6.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
sqlparse@0.5.0
0.6.0
1
dpage/pgadmin4:8.418cd5711fc9a
sqlparse@0.4.4
0.6.0
1
dpage/pgadmin4:7.537946e4f3e7b
sqlparse@0.4.4
0.6.0
1
dpage/pgadmin4:9.11.050700ac17936
sqlparse@0.5.4
0.6.0
1
dpage/pgadmin4:9.252cb72a9e3da
sqlparse@0.5.3
0.6.0
1
dpage/pgadmin4:8.13561c1f8f99f2
sqlparse@0.5.1
0.6.0
1
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.6.0
1
dpage/pgadmin4:4.22b1f00b8163cf
sqlparse@0.2.4
0.6.0
1
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.6.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
sqlparse@0.2.4
0.6.0
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
sqlparse@0.4.1
0.6.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
sqlparse@0.4.2
0.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.