StackRadar

CVE-2026-84305

Medium

Advisory

Published 1 Sept 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
149
deployed by those charts
Fix available
1 of 2
affected packages

sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 149 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+10 more0.6.0149
sqlparsedeb0.2.4-3no fix listed1
OSV records
GHSA-cfqr-cjx5-5jcmUBUNTU-CVE-2026-84305
Also known as
PYSEC-2026-3923

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
pgadmin4runixVerified publisher1.66.01 of 1See more

pgadmin4 runix 1.66.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.172f4ce946ddf8
sqlparse@0.5.5
0.6.0

Open the chart page →

398
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
sqlparse@0.4.4
0.6.0

Open the chart page →

11,367
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
sqlparse@0.4.2
0.6.0

Open the chart page →

9,145
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
langgenius/dify-api:1.16.1dcefa5f7c47c
sqlparse@0.5.4
0.6.0

Open the chart page →

22,002
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
sqlparse@0.5.3
0.6.0

Open the chart page →

16,251
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
sqlparse@0.5.0
0.6.0

Open the chart page →

5,987
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.6.0

Open the chart page →

5,851
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
sqlparse@0.5.5
0.6.0

Open the chart page →

4,332
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
sqlparse@0.3.1
0.6.0

Open the chart page →

30,326
home-assistantalekcVerified publisher2.11.21 of 1See more

home-assistant alekc 2.11.2

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
sqlparse@0.5.5
0.6.0

Open the chart page →

2,133
home-assistantandrenarchyVerified publisher14.103.01 of 1See more

home-assistant andrenarchy 14.103.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.1612d76760b54
sqlparse@0.5.5
0.6.0

Open the chart page →

2,133
baserowbaserow-chartVerified publisher1.0.561 of 6See more

baserow baserow-chart 1.0.56

1 of the 6 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
baserow/backend:2.3.37c00549b3a6f
sqlparse@0.5.5
0.6.0

Open the chart page →

17,263
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.6.0

Open the chart page →

52,919
pgadmincetic0.1.121 of 1See more

pgadmin cetic 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0

Open the chart page →

398
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
sqlparse@0.5.3
0.6.0

Open the chart page →

27,267
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
taigaio/taiga-back:6.4.29f97323cc150
sqlparse@0.4.1
0.6.0

Open the chart page →

7,255
netboxstartechnicaVerified publisher5.1.01 of 4See more

netbox startechnica 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
sqlparse@0.5.0
0.6.0

Open the chart page →

1,650
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
sqlparse@0.5.0
0.6.0

Open the chart page →

17,404
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
dpage/pgadmin4:7.537946e4f3e7b
sqlparse@0.4.4
0.6.0

Open the chart page →

14,546
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
redislabs/redisinsight:1.14.0b03ab1426d0d
sqlparse@0.4.4
0.6.0

Open the chart page →

13,874
healthchecksgabe565Verified publisher0.17.01 of 1See more

healthchecks gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
sqlparse@0.5.3
0.6.0

Open the chart page →

2,286
mlflowgetindataVerified publisher0.1.21 of 1See more

mlflow getindata 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
gcr.io/getindata-images-public/mlflow:latest25d6975951f1
sqlparse@0.5.0
0.6.0

Open the chart page →

2,452
home-assistanthome-assistantVerified publisher0.5.101 of 3See more

home-assistant home-assistant 0.5.10

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
sqlparse@0.5.5
0.6.0

Open the chart page →

2,331
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
sqlparse@0.5.5
0.6.0

Open the chart page →

4,634
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
flagsmith/flagsmith-api:v2.6.0fd58556339a4
sqlparse@0.4.1
0.6.0

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
sqlparse@0.4.2
0.6.0
kobotoolbox/kpi:2.022.24dbcacc01bccd4
sqlparse@0.4.2
0.6.0

Open the chart page →

18,517
open-zaakopen-zaak0.8.01 of 3See more

open-zaak open-zaak 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
openzaak/open-zaak:1.6.02ca2ea6e0ae9
sqlparse@0.4.2
0.6.0

Open the chart page →

4,045
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
sqlparse@0.5.5
0.6.0

Open the chart page →

9,770
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
wger/server:2.6997ead43aabd
sqlparse@0.5.5
0.6.0

Open the chart page →

8,491
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
sqlparse@0.5.3
0.6.0

Open the chart page →

12,037
psonoankra-chartsVerified publisher1.2.01 of 2See more

psono ankra-charts 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
psono/psono-server:5.0.03b974b43ea03
sqlparse@0.5.0
0.6.0

Open the chart page →

2,388
anteonanteonVerified publisher2.6.43 of 13See more

anteon anteon 2.6.4

3 of the 13 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
sqlparse@0.5.1
0.6.0
ddosify/selfhosted_backend:3.2.93c11e3182652
sqlparse@0.5.0
0.6.0
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
sqlparse@0.5.0
0.6.0

Open the chart page →

22,202
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
sqlparse@0.5.3
0.6.0

Open the chart page →

9,971
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
sqlparse@0.5.1
0.6.0

Open the chart page →

13,761
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.6.0

Open the chart page →

7,984
archerydoubanVerified publisher0.4.31 of 6See more

archery douban 0.4.3

1 of the 6 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
hhyo/archery:v1.9.11aa41843419e
sqlparse@0.4.3
0.6.0

Open the chart page →

5,853
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
sqlparse@0.5.1
0.6.0

Open the chart page →

10,858
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
sqlparse@0.5.3
0.6.0

Open the chart page →

8,496
pgadmin4folio-org1.2.301 of 1See more

pgadmin4 folio-org 1.2.30

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.22b1f00b8163cf
sqlparse@0.2.4
0.6.0

Open the chart page →

2,034
home-assistantgabe565Verified publisher0.17.01 of 1See more

home-assistant gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:latest612d76760b54
sqlparse@0.5.5
0.6.0

Open the chart page →

2,133
obicogabe565Verified publisher0.6.01 of 3See more

obico gabe565 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
sqlparse@0.5.3
0.6.0

Open the chart page →

1,965
healthchecksgeek-cookbookVerified publisher4.4.21 of 1See more

healthchecks geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
linuxserver/healthchecks:version-v1.20.050792a72fc71
sqlparse@0.4.1
0.6.0

Open the chart page →

1,667
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
sqlparse@0.4.2
0.6.0

Open the chart page →

3,924
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
sqlparse@0.4.2
0.6.0

Open the chart page →

7,801
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
sqlparse@0.5.0
0.6.0

Open the chart page →

12,397
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
sqlparse@0.3.0
0.6.0

Open the chart page →

7,129
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
sqlparse@0.5.0
0.6.0

Open the chart page →

20,403
aralib42Verified publisher0.4.61 of 1See more

ara lib42 0.4.6

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
recordsansible/ara-api:latest9dfd6e18f474
sqlparse@0.5.5
0.6.0

Open the chart page →

120
mlflow-controllermlflow-deployment-controller0.1.82 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

2 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
sqlparse@0.4.3
0.6.0
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
sqlparse@0.4.3
0.6.0

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
sqlparse@0.4.3
0.6.0

Open the chart page →

5,804

Container images carrying it

149 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dpage/pgadmin4:9.17:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0
5
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.6.0
3
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.6.0
3
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.6.0
2
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.6.0
2
safeglobal/safe-config-service:latest09a5e495c219
sqlparse@0.5.5
0.6.0
2
safeglobal/safe-transaction-service:latest80db836cc5d5
sqlparse@0.5.5
0.6.0
2
taigaio/taiga-back:latest4beed8f62c9f
sqlparse@0.5.3
0.6.0
2
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.6.0
2
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
sqlparse@0.5.5
0.6.0
2
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
sqlparse@0.5.5
0.6.0
2
alexeyr7/sf-test-app:latestdf0b41fdbd53
sqlparse@0.4.2
0.6.0
1
amancevice/superset:0.28.1c8c04bfe3d66
sqlparse@0.2.4
0.6.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
sqlparse@0.4.4
0.6.0
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
sqlparse@0.5.1
0.6.0
1
apache/airflow:2.8.1e5560ad0b86e
sqlparse@0.4.4
0.6.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
sqlparse@0.3.0
0.6.0
1
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.6.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
sqlparse@0.5.3
0.6.0
1
archivebox/archivebox:0.7.41a5a37331091
sqlparse@0.5.5
0.6.0
1
baserow/backend:2.3.37c00549b3a6f
sqlparse@0.5.5
0.6.0
1
baserow/backend:1.31.1e0b3c8130b91
sqlparse@0.5.0
0.6.0
1
baserow/baserow:1.30.1df0c42eb67e8
sqlparse@0.5.0
0.6.0
1
blackducksoftware/bdba-frontend:2026.6.3b10eaea94fd3
sqlparse@0.5.5
0.6.0
1
buntha/mlflow:2.1.1154542cc3083
sqlparse@0.4.3
0.6.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
sqlparse@0.4.4
0.6.0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
sqlparse@0.5.5
0.6.0
1
chorss/docker-pgadmin4:4.115c549cacb8ab
sqlparse@0.2.4
0.6.0
1
codecov/self-hosted-api:24.4.10475cb1c3136
sqlparse@0.4.4
0.6.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
sqlparse@0.4.4
0.6.0
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
sqlparse@0.5.3
0.6.0
1
datagrok/grok_spawner:latest8c2d48c1545c
sqlparse@0.5.5
0.6.0
1
datamate/seafile-professional:11.0.202dd66b722464
sqlparse@0.5.3
0.6.0
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
sqlparse@0.5.1
0.6.0
1
ddosify/selfhosted_backend:3.2.93c11e3182652
sqlparse@0.5.0
0.6.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
sqlparse@0.5.0
0.6.0
1
dpage/pgadmin4:8.418cd5711fc9a
sqlparse@0.4.4
0.6.0
1
dpage/pgadmin4:7.537946e4f3e7b
sqlparse@0.4.4
0.6.0
1
dpage/pgadmin4:9.11.050700ac17936
sqlparse@0.5.4
0.6.0
1
dpage/pgadmin4:9.252cb72a9e3da
sqlparse@0.5.3
0.6.0
1
dpage/pgadmin4:8.13561c1f8f99f2
sqlparse@0.5.1
0.6.0
1
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.6.0
1
dpage/pgadmin4:4.22b1f00b8163cf
sqlparse@0.2.4
0.6.0
1
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.6.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
sqlparse@0.2.4
0.6.0
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
sqlparse@0.4.1
0.6.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
sqlparse@0.4.2
0.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.