inbox-server-distributed Helm chart
appscodeVerified publisherScored 14 Sept 2026
Inbox Server by AppsCode
Latest 2025.12.25 3 days agodeploys tag 4.1.3 0Artifact Hub
inbox-server-distributed 2025.12.25 deploys 4 container images: library/cassandra, ghcr.io/appscode/inbox-server, opensearchproject/opensearch and library/rabbitmq. Across them, 1,283 findings — 10 critical, 16 high — 3 on CISA KEV. The highest contribution is GHSA-599f-7c49-w659 in commons-text 1.9, fixed in 1.10.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 4.1.3 | 4782421 | 5,916 |
| ghcr.io/ | latest | 1367271 | 3,963 |
| opensearchproject/ | 2.1.0 | 204276 | 1,789 |
| library/ | 3.12.1-management | 3667230 | 3,905 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2025-15649 | perl | no fix listed |
| Low | GO-2026-4603 | stdlib | 1.25.8 |
| Low | UBUNTU-CVE-2026-0864 | python3.10 | no fix listed |
| Low | UBUNTU-CVE-2026-29111 | systemd | 249.11-0ubuntu3.19 |
| Low | GO-2026-4982 | stdlib | 1.25.10 |
| Low | GO-2026-6091 | stdlib | 1.25.13 |
| Low | UBUNTU-CVE-2026-15059 | systemd | 249.11-0ubuntu3.22 |
| Low | UBUNTU-CVE-2024-56433 | shadow | no fix listed |
| Low | GHSA-pmhh-3w7g-xqp8 | jsoup | 1.23.1 |
| Low | UBUNTU-CVE-2026-41991 | gzip | 1.10-4ubuntu4.2 |
| Low | UBUNTU-CVE-2026-40226 | systemd | 249.11-0ubuntu3.21 |
| Low | GO-2025-3750 | stdlib | 1.23.10 |
| Low | GO-2026-4864 | stdlib | 1.25.9 |
| Low | GO-2025-3447 | stdlib | 1.22.12 |
| Low | GO-2026-4865 | stdlib | 1.25.9 |
| Low | GO-2026-4869 | stdlib | 1.25.9 |
| Low | GO-2026-4340 | stdlib | 1.24.12 |
| Low | GO-2025-4175 | stdlib | 1.24.11 |
| Low | UBUNTU-CVE-2025-4877 | libssh | 0.9.6-2ubuntu0.22.04.4 |
| Low | UBUNTU-CVE-2026-18374 | glibc | no fix listed |
| Low | UBUNTU-CVE-2026-16742 | systemd | 249.11-0ubuntu3.22 |
| Low | UBUNTU-CVE-2026-19542 | glibc | 2.35-0ubuntu3.15 |
| Low | UBUNTU-CVE-2026-53613 | util-linux | 2.37.2-4ubuntu3.6 |
| Low | UBUNTU-CVE-2026-53615 | util-linux | 2.37.2-4ubuntu3.6 |
| Low | UBUNTU-CVE-2026-77117 | glibc | 2.35-0ubuntu3.15 |
| Low | UBUNTU-CVE-2026-80489 | glibc | 2.35-0ubuntu3.15 |
| Low | UBUNTU-CVE-2025-68160 | openssl | 3.0.2-0ubuntu1.21 |
| Low | GHSA-659m-px2c-25wj | spring-core | no fix listed |
| Low | GO-2026-4403 | stdlib | 1.23.9 |
| Low | UBUNTU-CVE-2026-59845 | libssh | 0.9.6-2ubuntu0.22.04.8 |
| Low | UBUNTU-CVE-2023-29383 | shadow | no fix listed |
| Low | GO-2026-4970 | stdlib | 1.25.12 |
| Low | GHSA-jfvp-7x6p-h2pv | github.com/ | 1.1.14 |
| Low | UBUNTU-CVE-2025-15224 | curl | 7.81.0-1ubuntu1.22 |
| Low | UBUNTU-CVE-2026-42250 | bzip2 | 1.0.8-5ubuntu0.1 |
| Low | UBUNTU-CVE-2026-32777 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-39113 | sqlite3 | no fix listed |
| Low | UBUNTU-CVE-2025-9820 | gnutls28 | 3.7.3-4ubuntu1.8 |
| Low | UBUNTU-CVE-2026-0968 | libssh | 0.9.6-2ubuntu0.22.04.6 |
| Low | GO-2026-4602 | stdlib | 1.25.8 |
| Low | UBUNTU-CVE-2026-76957 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-27456 | util-linux | 2.37.2-4ubuntu3.6 |
| Low | GHSA-4wp7-92pw-q264 | spring-context | no fix listed |
| Low | UBUNTU-CVE-2026-18508 | tar | no fix listed |
| Low | UBUNTU-CVE-2025-8277 | libssh | 0.9.6-2ubuntu0.22.04.6 |
| Low | UBUNTU-CVE-2026-45186 | expat | no fix listed |
| Low | UBUNTU-CVE-2022-3219 | gnupg2 | no fix listed |
| Low | UBUNTU-CVE-2026-32776 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-41080 | expat | no fix listed |
| Low | GHSA-9f52-rjqv-25qv | spring-expression | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2025.12.25latest | 3 days ago | 4.1.3 | 1016258998 | 15,573 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.