StackRadar

airbyte Helm chart

airbyte-v2Verified publisher

Scored 14 Sept 2026

Helm chart to deploy airbyte

Latest 2.2.0 1 month agoapp version 2.2.0 0Artifact Hub

airbyte 2.2.0 deploys 10 container images: airbyte/cron, airbyte/manifest-server, airbyte/server, temporalio/auto-setup and 6 more. Across them, 1,145 findings1 critical, 8 high 2 on CISA KEV. The highest contribution is RHSA-2024:3339 in glibc 2.34-83.el9_3.7, fixed in 0:2.34-100.el9_4.2.

Radar Score

12,47318193943

1,145 findings over 10 of 10 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

10 images
ImageTagVulnerabilitiesRadar Score
airbyte/cron2.2.0001452753
airbyte/manifest-server7.23.702512473,277
airbyte/server2.2.0001559835
temporalio/auto-setup1.27.201201331,465
airbyte/worker2.2.0001655810
airbyte/workload-api-server2.2.0001554786
airbyte/workload-launcher2.2.0001455790
airbyte/bootloader2.2.0001452753
minio/minio×2RELEASE.2023-11-20T22-40-07Z14171521,958
airbyte/db2.2.00117841,046

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

638 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-41080expat@2.5.0-1+deb12u2no fix listed
LowDEBIAN-CVE-2011-3374apt@2.6.1no fix listed
LowGHSA-w573-9ffj-6ff9netty-transport-native-epoll@4.2.9.Final4.2.15.Final
LowGHSA-w573-9ffj-6ff9netty-transport-native-kqueue@4.2.9.Final4.2.15.Final
LowALPINE-CVE-2025-69418openssl@3.3.3-r03.3.6-r0
LowDEBIAN-CVE-2007-5686shadow@1:4.13+dfsg1-1+deb12u1no fix listed
LowGO-2026-5024golang.org/x/sys@v0.13.00.44.0
LowDEBIAN-CVE-2026-18477tar@1.34+dfsg-1.2+deb12u1no fix listed
LowDEBIAN-CVE-2026-73281openssh@1:9.2p1-2+deb12u10no fix listed
LowDEBIAN-CVE-2026-19499glibc@2.36-9+deb12u13no fix listed
LowDEBIAN-CVE-2026-19542glibc@2.36-9+deb12u13no fix listed
LowDEBIAN-CVE-2026-53613util-linux@2.38.1-5+deb12u3no fix listed
LowDEBIAN-CVE-2026-53615util-linux@2.38.1-5+deb12u3no fix listed
LowDEBIAN-CVE-2026-77117glibc@2.36-9+deb12u13no fix listed
LowDEBIAN-CVE-2026-80489glibc@2.36-9+deb12u13no fix listed
LowGO-2026-5841github.com/klauspost/compress@v1.16.71.18.7
LowGO-2026-5932golang.org/x/crypto@v0.14.0no fix listed
LowGO-2026-6061google.golang.org/grpc@v1.58.31.82.1
LowGO-2026-6278github.com/gorilla/websocket@v1.5.01.5.3
LowALPINE-CVE-2025-46394busybox@1.37.0-r121.37.0-r14
LowDEBIAN-CVE-2026-40228systemd@252.39-1~deb12u1no fix listed
LowGHSA-5239-wwwm-4pmqpygments@2.19.12.20.0
LowGHSA-gm2g-2xr9-pxxjgo.temporal.io/server@v0.0.0-20250327224552-a31fd7a9e5db1.20.0
LowGHSA-j88v-2chj-qfwxgithub.com/jackc/pgx/v5@v5.7.25.9.2
LowDEBIAN-CVE-2011-4116perl@5.36.0-7+deb12u3no fix listed
LowGHSA-73h3-mf4w-8647poetry@2.0.12.3.4
LowDEBIAN-CVE-2026-57062gnupg2@2.2.40-1.1+deb12u1no fix listed
LowGHSA-p47f-322f-whfhlogback-core@1.5.321.5.33
LowGHSA-6vgw-5pg2-w6jppip@25.226.0
LowDEBIAN-CVE-2026-53910diffutils@1:3.8-4no fix listed
LowGHSA-xpg8-3hhp-p7w8go.temporal.io/server@v0.0.0-20250327224552-a31fd7a9e5db1.29.5
LowDEBIAN-CVE-2026-24515expat@2.5.0-1+deb12u2no fix listed
LowALPINE-CVE-2024-58251busybox@1.37.0-r121.37.0-r14
LowDEBIAN-CVE-2026-89156pcre2@10.42-110.42-1+deb12u1
LowDEBIAN-CVE-2026-73283openssh@1:9.2p1-2+deb12u10no fix listed
LowDEBIAN-CVE-2026-5958sed@4.9-14.9-1+deb12u1
LowDEBIAN-CVE-2026-6368glibc@2.36-9+deb12u13no fix listed
LowGHSA-q9w6-cwj4-gf4pgo.temporal.io/api@v1.18.11.44.1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.2.0latest1 month ago2.2.01819394312,473

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/airbyte-v2/airbyte.svg)](https://charts.stackradar.io/charts/airbyte-v2/airbyte)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.