inbox-server-distributed Helm chart
appscodeVerified publisherScored 14 Sept 2026
Inbox Server by AppsCode
Latest 2025.12.25 3 days agodeploys tag 4.1.3 0Artifact Hub
inbox-server-distributed 2025.12.25 deploys 4 container images: library/cassandra, ghcr.io/appscode/inbox-server, opensearchproject/opensearch and library/rabbitmq. Across them, 1,283 findings — 10 critical, 16 high — 3 on CISA KEV. The highest contribution is GHSA-599f-7c49-w659 in commons-text 1.9, fixed in 1.10.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 4.1.3 | 4782421 | 5,916 |
| ghcr.io/ | latest | 1367271 | 3,963 |
| opensearchproject/ | 2.1.0 | 204276 | 1,789 |
| library/ | 3.12.1-management | 3667230 | 3,905 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | GHSA-599f-7c49-w659 | commons-text | 1.10.0 |
| Critical | GHSA-rxpj-7qvf-xv32KEV | activemq-broker | 6.2.3 |
| Critical | GHSA-mjmj-j48q-9wg2 | snakeyaml | 2.0 |
| Critical | UBUNTU-CVE-2025-27363KEV | freetype | 2.11.1+dfsg-1ubuntu0.3 |
| Critical | UBUNTU-CVE-2023-4911KEV | glibc | 2.35-0ubuntu3.4 |
| Critical | UBUNTU-CVE-2025-6965 | sqlite3 | 3.37.2-2ubuntu0.5 |
| Critical | UBUNTU-CVE-2024-2961 | glibc | 2.35-0ubuntu3.7 |
| High | UBUNTU-CVE-2025-15467 | openssl | 3.0.2-0ubuntu1.21 |
| High | UBUNTU-CVE-2024-6119 | openssl | no fix listed |
| High | UBUNTU-CVE-2007-4559 | python3.10 | 3.10.12-1~22.04.2 |
| High | UBUNTU-CVE-2024-2398 | curl | 7.81.0-1ubuntu1.16 |
| High | UBUNTU-CVE-2023-2650 | openssl | 3.0.2-0ubuntu1.10+Fips1 |
| High | UBUNTU-CVE-2024-28182 | nghttp2 | 1.43.0-1ubuntu0.2 |
| High | GHSA-xr7r-f8xq-vfvv | github.com/ | 1.1.12 |
| High | UBUNTU-CVE-2024-2511 | openssl | no fix listed |
| High | UBUNTU-CVE-2024-3596 | krb5 | 1.19.2-2ubuntu0.5 |
| Medium | GO-2024-2687 | stdlib | 1.21.9 |
| Medium | GHSA-3f7h-mf4q-vrm4 | woodstox-core | 6.4.0 |
| Medium | UBUNTU-CVE-2024-7264 | curl | 7.81.0-1ubuntu1.17 |
| Medium | UBUNTU-CVE-2024-5535 | openssl | no fix listed |
| Medium | GHSA-w3w2-mpp5-92gm | activemq-broker | 6.2.5 |
| Medium | UBUNTU-CVE-2020-10735 | python3.10 | no fix listed |
| Medium | UBUNTU-CVE-2022-48522 | perl | 5.34.0-3ubuntu1.3 |
| Medium | UBUNTU-CVE-2026-45447 | openssl | 3.0.2-0ubuntu1.25 |
| Medium | GHSA-g5mm-vmx4-3rg7 | spring-context | 5.2.21.RELEASE |
| Medium | GHSA-x3x3-qwjq-8gj4 | cxf-core | 3.4.10 |
| Medium | GHSA-57j2-w4cx-62h2 | jackson-databind | 2.13.2.1 |
| Medium | UBUNTU-CVE-2021-46848 | libtasn1-6 | 4.18.0-4ubuntu0.2 |
| Medium | UBUNTU-CVE-2024-45490 | expat | 2.4.7-1ubuntu0.4 |
| Medium | GHSA-mmxm-8w33-wc4h | jetty-http2-common | 12.0.25 |
| Medium | UBUNTU-CVE-2023-5363 | openssl | 3.0.2-0ubuntu1.12 |
| Medium | UBUNTU-CVE-2024-37371 | krb5 | 1.19.2-2ubuntu0.4 |
| Medium | GHSA-98qh-xjc8-98pq | postgresql | 42.7.11 |
| Medium | GHSA-7r82-7xv7-xcpj | httpclient | 4.5.13 |
| Medium | UBUNTU-CVE-2017-11164 | pcre3 | no fix listed |
| Medium | GHSA-wxr5-93ph-8wr9 | commons-beanutils | 1.11.0 |
| Medium | UBUNTU-CVE-2024-4741 | openssl | no fix listed |
| Medium | GHSA-jjjh-jjxp-wpff | jackson-databind | 2.13.4.2 |
| Medium | GHSA-rgv9-q543-rqg4 | jackson-databind | 2.13.4 |
| Medium | GHSA-735f-pc8j-v9w8 | protobuf-java | 3.25.5 |
| Medium | GHSA-3mc7-4q67-w48m | snakeyaml | 1.31 |
| Medium | UBUNTU-CVE-2026-19931 | curl | no fix listed |
| Medium | GHSA-6phf-6h5g-97j2 | sqlite-jdbc | 3.41.2.2 |
| Medium | UBUNTU-CVE-2022-40735 | openssl | no fix listed |
| Medium | UBUNTU-CVE-2023-3446 | openssl | 3.0.2-0ubuntu1.12 |
| Medium | UBUNTU-CVE-2024-7592 | python3.10 | 3.10.12-1~22.04.6 |
| Medium | UBUNTU-CVE-2016-20013 | glibc | no fix listed |
| Medium | UBUNTU-CVE-2024-6232 | python3.10 | 3.10.12-1~22.04.6 |
| Medium | UBUNTU-CVE-2023-31486 | perl | no fix listed |
| Medium | GHSA-fh5r-crhr-qrrq | cxf-core | 3.5.10 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2025.12.25latest | 3 days ago | 4.1.3 | 1016258998 | 15,573 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.