inbox-server-distributed Helm chart
appscodeVerified publisherScored 14 Sept 2026
Inbox Server by AppsCode
Latest 2025.12.25 3 days agodeploys tag 4.1.3 0Artifact Hub
inbox-server-distributed 2025.12.25 deploys 4 container images: library/cassandra, ghcr.io/appscode/inbox-server, opensearchproject/opensearch and library/rabbitmq. Across them, 1,283 findings — 10 critical, 16 high — 3 on CISA KEV. The highest contribution is GHSA-599f-7c49-w659 in commons-text 1.9, fixed in 1.10.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 4.1.3 | 4782421 | 5,916 |
| ghcr.io/ | latest | 1367271 | 3,963 |
| opensearchproject/ | 2.1.0 | 204276 | 1,789 |
| library/ | 3.12.1-management | 3667230 | 3,905 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2025-8058 | glibc | 2.35-0ubuntu3.11 |
| Low | GHSA-h2h4-5m64-m273 | activemq-client | 6.2.2 |
| Low | GHSA-h2h4-5m64-m273 | activemq-broker | 6.2.2 |
| Low | UBUNTU-CVE-2024-11168 | python3.10 | 3.10.12-1~22.04.8 |
| Low | GO-2025-4011 | stdlib | 1.24.8 |
| Low | GO-2025-4015 | stdlib | 1.24.8 |
| Low | GO-2026-6218 | stdlib | 1.25.13 |
| Low | UBUNTU-CVE-2026-40930 | libpng1.6 | 1.6.37-3ubuntu0.6 |
| Low | UBUNTU-CVE-2025-64506 | libpng1.6 | 1.6.37-3ubuntu0.1 |
| Low | UBUNTU-CVE-2025-45582 | tar | 1.34+dfsg-1ubuntu0.1.22.04.4 |
| Low | UBUNTU-CVE-2026-15534 | perl | 5.34.0-3ubuntu1.9 |
| Low | GO-2025-3373 | stdlib | 1.22.11 |
| Low | UBUNTU-CVE-2025-8291 | python3.10 | 3.10.12-1~22.04.12 |
| Low | GO-2025-4155 | stdlib | 1.24.11 |
| Low | UBUNTU-CVE-2025-14017 | curl | 7.81.0-1ubuntu1.22 |
| Low | GO-2024-2888 | stdlib | 1.21.11 |
| Low | GO-2025-4008 | stdlib | 1.24.8 |
| Low | GO-2025-4010 | stdlib | 1.24.8 |
| Low | UBUNTU-CVE-2024-10041 | pam | no fix listed |
| Low | UBUNTU-CVE-2026-59850 | libssh | 0.9.6-2ubuntu0.22.04.8 |
| Low | GHSA-6g3j-p5g6-992f | opensearch | 2.11.1 |
| Low | GO-2023-1840 | stdlib | 1.19.10 |
| Low | UBUNTU-CVE-2025-0167 | curl | 7.81.0-1ubuntu1.23 |
| Low | UBUNTU-CVE-2026-50812 | sqlite3 | 3.37.2-2ubuntu0.7 |
| Low | GO-2025-4014 | stdlib | 1.24.8 |
| Low | UBUNTU-CVE-2023-4641 | shadow | 1:4.8.1-2ubuntu2.2 |
| Low | UBUNTU-CVE-2026-34757 | libpng1.6 | 1.6.37-3ubuntu0.5 |
| Low | GO-2025-3503 | stdlib | 1.23.7 |
| Low | UBUNTU-CVE-2026-18938 | p11-kit | 0.24.0-6ubuntu0.1 |
| Low | GHSA-wf8f-6423-gfxg | jackson-core | 2.13.0 |
| Low | GO-2026-4976 | stdlib | 1.25.10 |
| Low | UBUNTU-CVE-2025-5278 | coreutils | 8.32-4.1ubuntu1.4 |
| Low | GO-2026-5856 | stdlib | 1.25.12 |
| Low | UBUNTU-CVE-2026-22795 | openssl | 3.0.2-0ubuntu1.21 |
| Low | GO-2025-4007 | stdlib | 1.24.9 |
| Low | GHSA-5m9f-rphj-c435 | amqp-client | 5.33.0 |
| Low | GO-2026-4980 | stdlib | 1.25.10 |
| Low | UBUNTU-CVE-2026-42770 | openssl | 3.0.2-0ubuntu1.25 |
| Low | GO-2026-5039 | stdlib | 1.25.11 |
| Low | GHSA-wh89-7897-x99h | netty-codec-haproxy | 4.1.136.Final |
| Low | UBUNTU-CVE-2025-6075 | python3.10 | 3.10.12-1~22.04.12 |
| Low | UBUNTU-CVE-2025-8114 | libssh | 0.9.6-2ubuntu0.22.04.5 |
| Low | GO-2025-4013 | stdlib | 1.24.8 |
| Low | GO-2025-3849 | stdlib | 1.23.12 |
| Low | GO-2026-4946 | stdlib | 1.25.9 |
| Low | UBUNTU-CVE-2026-54370 | acl | no fix listed |
| Low | UBUNTU-CVE-2026-56412 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56131 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-50219 | expat | no fix listed |
| Low | UBUNTU-CVE-2025-15649 | perl | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2025.12.25latest | 3 days ago | 4.1.3 | 1016258998 | 15,573 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.