StackRadar

CVE-2026-84305

Medium

Advisory

Published 1 Sept 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
149
deployed by those charts
Fix available
1 of 2
affected packages

sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 149 images.

Affected packageAffected versionsFixed inImages
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+10 more0.6.0149
sqlparsedeb0.2.4-3no fix listed1
OSV records
GHSA-cfqr-cjx5-5jcmUBUNTU-CVE-2026-84305
Also known as
PYSEC-2026-3923

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
sqlparse@0.5.3
0.6.0

Open the chart page →

6,873
open-notificatiesopen-zaak0.7.01 of 4See more

open-notificaties open-zaak 0.7.0

1 of the 4 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
openzaak/open-notificaties:1.3.02e65313b9b10
sqlparse@0.4.2
0.6.0

Open the chart page →

2,850
home-assistantpree-helm-chartsVerified publisher1.80.01 of 1See more

home-assistant pree-helm-charts 1.80.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
sqlparse@0.5.5
0.6.0

Open the chart page →

2,133
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
sqlparse@0.5.5
0.6.0

Open the chart page →

8,158
sceptresceptreai0.1.122 of 5See more

sceptre sceptreai 0.1.12

2 of the 5 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
sqlparse@0.5.5
0.6.0
maponyacharles/sceptreai:api-0.1.127b37b092130a
sqlparse@0.5.5
0.6.0

Open the chart page →

4,369
sentry-k8ssentry-k8sVerified publisher1.4.12 of 11See more

sentry-k8s sentry-k8s 1.4.1

2 of the 11 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
sqlparse@0.5.4
0.6.0
ghcr.io/getsentry/snuba:26.7.210f8d164109b
sqlparse@0.5.4
0.6.0

Open the chart page →

16,449
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
sqlparse@0.4.3
0.6.0

Open the chart page →

2,236
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
sqlparse@0.2.2
0.6.0

Open the chart page →

24,930
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
sqlparse@0.5.3
0.6.0

Open the chart page →

9,148
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
sqlparse@0.5.0
0.6.0

Open the chart page →

2,233
waldurwaldur-chartsVerified publisher8.1.21 of 3See more

waldur waldur-charts 8.1.2

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
opennode/waldur-mastermind:8.1.24c82b15d9042
sqlparse@0.5.5
0.6.0

Open the chart page →

4,839
qleverzazukoVerified publisher0.7.01 of 2See more

qlever zazuko 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
sqlparse@0.5.5
0.6.0

Open the chart page →

2,900
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
sqlparse@0.5.5
0.6.0

Open the chart page →

7,239
ddosifyanteonVerified publisher1.7.53 of 13See more

ddosify anteon 1.7.5

3 of the 13 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlparse@0.4.4
0.6.0
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlparse@0.4.4
0.6.0
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
sqlparse@0.4.4
0.6.0

Open the chart page →

25,669
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
sqlparse@0.5.4
0.6.0

Open the chart page →

1,565
argonix-apiargonix0.2.01 of 4See more

argonix-api argonix 0.2.0

1 of the 4 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.068e17a8aaa40
sqlparse@0.5.5
0.6.0

Open the chart page →

4,923
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.6.0

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.6.0

Open the chart page →

2,418
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
sqlparse@0.4.1
0.6.0
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
sqlparse@0.4.1
0.6.0

Open the chart page →

22,568
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.6.0

Open the chart page →

10,061
shynetatrox0.1.11 of 1See more

shynet atrox 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.12.0e821e31140f7
sqlparse@0.4.2
0.6.0

Open the chart page →

5,507
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
sqlparse@0.4.1
0.6.0

Open the chart page →

22,891
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
sqlparse@0.5.0
0.6.0

Open the chart page →

10,145
bdbablackduck2026.6.31 of 9See more

bdba blackduck 2026.6.3

1 of the 9 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
blackducksoftware/bdba-frontend:2026.6.3b10eaea94fd3
sqlparse@0.5.5
0.6.0

Open the chart page →

9,521
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
sqlparse@0.4.4
0.6.0

Open the chart page →

2,507
opencvecfi20170.1.22 of 7See more

opencve cfi2017 0.1.2

2 of the 7 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
sqlparse@0.5.3
0.6.0
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
sqlparse@0.5.5
0.6.0

Open the chart page →

15,371
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
sqlparse@0.2.4
0.6.0

Open the chart page →

5,060
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.6.0

Open the chart page →

12,457
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.6.0

Open the chart page →

12,131
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.6.0

Open the chart page →

11,592
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
sqlparse@0.5.5
0.6.0

Open the chart page →

4,601
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
sqlparse@0.4.2
0.6.0

Open the chart page →

16,069
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
sqlparse@0.1.16
0.6.0

Open the chart page →

70,895
authentikcluster-deploy0.2.01 of 1See more

authentik cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
sqlparse@0.5.5
0.6.0

Open the chart page →

2,481
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.4.0b4e849fcf94a
sqlparse@0.5.0
0.6.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
sqlparse@0.4.4
0.6.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
sqlparse@0.5.0
0.6.0

Open the chart page →

6,632
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
sqlparse@0.5.0
0.6.0

Open the chart page →

5,062
datagrokdatagrok1.0.31 of 7See more

datagrok datagrok 1.0.3

1 of the 7 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
datagrok/grok_spawner:latest8c2d48c1545c
sqlparse@0.5.5
0.6.0

Open the chart page →

2,328
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
sqlparse@0.5.1
0.6.0

Open the chart page →

6,075
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.6.0

Open the chart page →

4,422
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
sqlparse@0.4.3
0.6.0

Open the chart page →

14,856
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
alexeyr7/sf-test-app:latestdf0b41fdbd53
sqlparse@0.4.2
0.6.0

Open the chart page →

2,548
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
sqlparse@0.5.5
0.6.0

Open the chart page →

7,459
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
sqlparse@0.4.4
0.6.0
codecov/self-hosted-worker:24.4.1837f546b479b
sqlparse@0.4.4
0.6.0

Open the chart page →

24,917
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
sqlparse@0.5.5
0.6.0

Open the chart page →

2,158
pgadmin4eks-storageclass0.1.01 of 2See more

pgadmin4 eks-storageclass 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0

Open the chart page →

398
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
sqlparse@0.4.3
0.6.0

Open the chart page →

25,122
escvmschedulerescvmscheduler1.0.71 of 3See more

escvmscheduler escvmscheduler 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
sqlparse@0.4.3
0.6.0

Open the chart page →

4,678
infrafibonacci-cluster-infraVerified publisher1.0.01 of 4See more

infra fibonacci-cluster-infra 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-84305.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.418cd5711fc9a
sqlparse@0.4.4
0.6.0

Open the chart page →

12,454

Container images carrying it

149 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dpage/pgadmin4:9.17:latest2f4ce946ddf8
sqlparse@0.5.5
0.6.0
5
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.6.0
3
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.6.0
3
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.6.0
2
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.6.0
2
safeglobal/safe-config-service:latest09a5e495c219
sqlparse@0.5.5
0.6.0
2
safeglobal/safe-transaction-service:latest80db836cc5d5
sqlparse@0.5.5
0.6.0
2
taigaio/taiga-back:latest4beed8f62c9f
sqlparse@0.5.3
0.6.0
2
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.6.0
2
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
sqlparse@0.5.5
0.6.0
2
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
sqlparse@0.5.5
0.6.0
2
alexeyr7/sf-test-app:latestdf0b41fdbd53
sqlparse@0.4.2
0.6.0
1
amancevice/superset:0.28.1c8c04bfe3d66
sqlparse@0.2.4
0.6.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
sqlparse@0.4.4
0.6.0
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
sqlparse@0.5.1
0.6.0
1
apache/airflow:2.8.1e5560ad0b86e
sqlparse@0.4.4
0.6.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
sqlparse@0.3.0
0.6.0
1
apache/superset:4.0.1ab9467fd712c
sqlparse@0.4.4
0.6.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
sqlparse@0.5.3
0.6.0
1
archivebox/archivebox:0.7.41a5a37331091
sqlparse@0.5.5
0.6.0
1
baserow/backend:2.3.37c00549b3a6f
sqlparse@0.5.5
0.6.0
1
baserow/backend:1.31.1e0b3c8130b91
sqlparse@0.5.0
0.6.0
1
baserow/baserow:1.30.1df0c42eb67e8
sqlparse@0.5.0
0.6.0
1
blackducksoftware/bdba-frontend:2026.6.3b10eaea94fd3
sqlparse@0.5.5
0.6.0
1
buntha/mlflow:2.1.1154542cc3083
sqlparse@0.4.3
0.6.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
sqlparse@0.4.4
0.6.0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
sqlparse@0.5.5
0.6.0
1
chorss/docker-pgadmin4:4.115c549cacb8ab
sqlparse@0.2.4
0.6.0
1
codecov/self-hosted-api:24.4.10475cb1c3136
sqlparse@0.4.4
0.6.0
1
codecov/self-hosted-worker:24.4.1837f546b479b
sqlparse@0.4.4
0.6.0
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
sqlparse@0.5.3
0.6.0
1
datagrok/grok_spawner:latest8c2d48c1545c
sqlparse@0.5.5
0.6.0
1
datamate/seafile-professional:11.0.202dd66b722464
sqlparse@0.5.3
0.6.0
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
sqlparse@0.5.1
0.6.0
1
ddosify/selfhosted_backend:3.2.93c11e3182652
sqlparse@0.5.0
0.6.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_hammermanager:1.2.471b8768f49bc
sqlparse@0.4.4
0.6.0
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
sqlparse@0.5.0
0.6.0
1
dpage/pgadmin4:8.418cd5711fc9a
sqlparse@0.4.4
0.6.0
1
dpage/pgadmin4:7.537946e4f3e7b
sqlparse@0.4.4
0.6.0
1
dpage/pgadmin4:9.11.050700ac17936
sqlparse@0.5.4
0.6.0
1
dpage/pgadmin4:9.252cb72a9e3da
sqlparse@0.5.3
0.6.0
1
dpage/pgadmin4:8.13561c1f8f99f2
sqlparse@0.5.1
0.6.0
1
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.6.0
1
dpage/pgadmin4:4.22b1f00b8163cf
sqlparse@0.2.4
0.6.0
1
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.6.0
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
sqlparse@0.2.4
0.6.0
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
sqlparse@0.4.1
0.6.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
sqlparse@0.4.2
0.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.