inbox-server-distributed 2025.12.25 Helm chart
appscodeVerified publisherScored 14 Sept 2026
Inbox Server by AppsCode
Version 2025.12.25 3 days agodeploys tag 4.1.3 0Artifact Hub
inbox-server-distributed 2025.12.25 deploys 4 container images: library/cassandra, ghcr.io/appscode/inbox-server, opensearchproject/opensearch and library/rabbitmq. Across them, 1,283 findings — 10 critical, 16 high — 3 on CISA KEV. The highest contribution is GHSA-599f-7c49-w659 in commons-text 1.9, fixed in 1.10.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 4.1.3 | 4782421 | 5,916 |
| ghcr.io/ | latest | 1367271 | 3,963 |
| opensearchproject/ | 2.1.0 | 204276 | 1,789 |
| library/ | 3.12.1-management | 3667230 | 3,905 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2025-15079 | curl | 7.81.0-1ubuntu1.22 |
| Low | GO-2023-1569 | stdlib | 1.19.6 |
| Low | UBUNTU-CVE-2025-12781 | python3.10 | no fix listed |
| Low | UBUNTU-CVE-2025-15366 | python3.10 | 3.10.12-1~22.04.15 |
| Low | GHSA-g2j6-57v7-gm8c | github.com/ | 1.1.5 |
| Low | GO-2023-2382 | stdlib | 1.20.12 |
| Low | UBUNTU-CVE-2026-6429 | curl | 7.81.0-1ubuntu1.24 |
| Low | GO-2022-1143 | stdlib | 1.18.9 |
| Low | UBUNTU-CVE-2024-22365 | pam | 1.4.0-11ubuntu2.4 |
| Low | GHSA-c69g-56f8-xwqj | netty-codec-http2 | 4.1.136.Final |
| Low | UBUNTU-CVE-2026-22796 | openssl | 3.0.2-0ubuntu1.21 |
| Low | GHSA-hf52-78x8-6w3w | activemq-broker | 6.2.6 |
| Low | GO-2024-2599 | stdlib | 1.21.8 |
| Low | GO-2022-1038 | stdlib | 1.18.7 |
| Low | GO-2024-3106 | stdlib | 1.22.7 |
| Low | GHSA-hjcp-jmpx-g3qm | httpclient5 | 5.6.3 |
| Low | GHSA-68m8-v89j-7j2p | bc-fips | 1.0.2.4 |
| Low | UBUNTU-CVE-2026-1965 | curl | 7.81.0-1ubuntu1.23 |
| Low | GO-2023-1570 | stdlib | 1.19.6 |
| Low | UBUNTU-CVE-2025-3576 | krb5 | 1.19.2-2ubuntu0.7 |
| Low | UBUNTU-CVE-2025-68973 | gnupg2 | 2.2.27-3ubuntu2.5 |
| Low | UBUNTU-CVE-2026-7168 | curl | 7.81.0-1ubuntu1.24 |
| Low | GHSA-337m-mw94-2v6g | commons-configuration2 | 2.15.0 |
| Low | GO-2022-0531 | stdlib | 1.17.11 |
| Low | GO-2024-2600 | stdlib | 1.21.8 |
| Low | UBUNTU-CVE-2025-15367 | python3.10 | 3.10.12-1~22.04.15 |
| Low | UBUNTU-CVE-2026-59847 | libssh | 0.9.6-2ubuntu0.22.04.8 |
| Low | GHSA-38f8-5428-x5cv | netty-codec-http | 4.1.133.Final |
| Low | GHSA-xq3w-v528-46rv | netty-common | 4.1.115.Final |
| Low | UBUNTU-CVE-2026-3783 | curl | 7.81.0-1ubuntu1.23 |
| Low | UBUNTU-CVE-2026-4873 | curl | 7.81.0-1ubuntu1.24 |
| Low | UBUNTU-CVE-2023-39804 | tar | 1.34+dfsg-1ubuntu0.1.22.04.2 |
| Low | GHSA-8c42-7qj2-3j46 | netty-codec-http | 4.1.137.Final |
| Low | GO-2024-2609 | stdlib | 1.21.8 |
| Low | UBUNTU-CVE-2026-34743 | xz-utils | 5.2.5-2ubuntu1.1 |
| Low | GO-2024-3107 | stdlib | 1.22.7 |
| Low | GO-2023-1751 | stdlib | 1.19.9 |
| Low | GO-2023-1753 | stdlib | 1.19.9 |
| Low | GHSA-r7wm-3cxj-wff9 | jackson-core | 2.21.4 |
| Low | UBUNTU-CVE-2026-54411 | pam | 1.4.0-11ubuntu2.7 |
| Low | GHSA-389x-839f-4rhx | netty-common | 4.1.118.Final |
| Low | UBUNTU-CVE-2026-84366 | python3.10 | no fix listed |
| Low | UBUNTU-CVE-2026-25210 | expat | 2.4.7-1ubuntu0.7 |
| Low | GHSA-4mp9-239f-g9hg | netty-codec-http | 4.1.136.Final |
| Low | UBUNTU-CVE-2026-19487 | perl | 5.34.0-3ubuntu1.9 |
| Low | UBUNTU-CVE-2026-4878 | libcap2 | 1:2.44-1ubuntu0.22.04.3 |
| Low | GO-2023-2041 | stdlib | 1.20.8 |
| Low | GO-2023-2043 | stdlib | 1.20.8 |
| Low | GO-2022-0515 | stdlib | 1.17.12 |
| Low | GO-2023-2186 | stdlib | 1.20.11 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2025.12.25latest | 3 days ago | 4.1.3 | 1016258998 | 15,573 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.