StackRadar

artifact-hub Helm chart

artifact-hubVerified publisher

Scored 14 Sept 2026

Artifact Hub is a web-based application that enables finding, installing, and publishing Cloud Native packages.

Latest 1.23.0 2 months agoapp version 1.23.0 95Artifact Hub

artifact-hub 1.23.0 deploys 7 container images: artifacthub/postgres, bitnamilegacy/kubectl, artifacthub/hub, aquasec/trivy and 3 more. Across them, 1,069 findings0 critical, 6 high 4 on CISA KEV. The highest contribution is DEBIAN-CVE-2025-15467 in openssl 3.5.1-1, fixed in 3.5.4-1~deb13u2. Chart.yaml declares kubeVersion >= 1.19.0-0; rendered for Kubernetes 1.19.0.

Radar Score

10,75506148915

1,069 findings over 7 of 7 images measured

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

7 images
ImageTagVulnerabilitiesRadar Score
artifacthub/postgres×5latest01422222,676
bitnamilegacy/kubectl1.19011633807
artifacthub/hubv1.23.001450500
aquasec/trivy0.69.300341972,341
artifacthub/db-migratorv1.23.0011836737
artifacthub/scannerv1.23.001121421,402
artifacthub/trackerv1.23.001222352,292

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

101 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumDSA-5169-1openssl@1.1.1d-0+deb10u71.1.1n-0+deb10u3
MediumDLA-3807-1glibc@2.28-102.28-10+deb10u3
MediumGHSA-5cgq-3rg8-m6cvgolang.org/x/crypto@v0.46.00.52.0
MediumDLA-3804-1nghttp2@1.36.0-2+deb10u11.36.0-2+deb10u3
MediumDSA-5139-1openssl@1.1.1d-0+deb10u71.1.1n-0+deb10u2
MediumDLA-3449-1openssl@1.1.1d-0+deb10u71.1.1n-0+deb10u5
MediumDSA-5103-1openssl@1.1.1d-0+deb10u71.1.1d-0+deb10u8
MediumDSA-5140-1openldap@2.4.47+dfsg-3+deb10u62.4.47+dfsg-3+deb10u7
MediumDLA-3325-1openssl@1.1.1d-0+deb10u71.1.1n-0+deb10u4
MediumDSA-5111-1zlib@1:1.2.11.dfsg-11:1.2.11.dfsg-1+deb10u1
MediumDSA-6113-1openssl@3.5.1-13.5.4-1~deb13u2
MediumDEBIAN-CVE-2019-1010022glibc@2.41-12+deb13u3no fix listed
MediumDEBIAN-CVE-2017-17740openldap@2.6.10+dfsg-1no fix listed
MediumALPINE-CVE-2026-45447openssl@3.5.5-r03.5.7-r0
MediumDEBIAN-CVE-2026-45447openssl@3.5.1-13.5.6-1~deb13u2
MediumDEBIAN-CVE-2018-20796glibc@2.41-12+deb13u3no fix listed
MediumGHSA-v778-237x-gjrcgolang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb830.31.0
MediumDEBIAN-CVE-2015-3276openldap@2.6.10+dfsg-1no fix listed
MediumDEBIAN-CVE-2019-1010023glibc@2.41-12+deb13u3no fix listed
MediumDLA-3085-1curl@7.64.0-4+deb10u27.64.0-4+deb10u3
MediumGHSA-8c26-wmh5-6g9vgolang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb830.0.0-20220314234659-1baeb1ce4c0b
MediumGHSA-p77j-4mvh-x3m3google.golang.org/grpc@v1.78.01.79.3
MediumDLA-3103-1zlib@1:1.2.11.dfsg-11:1.2.11.dfsg-1+deb10u2
MediumALPINE-CVE-2026-19931curl@8.17.0-r18.22.0-r0
MediumDEBIAN-CVE-2025-11187openssl@3.5.1-13.5.4-1~deb13u2
MediumGHSA-7jwh-3vrq-q3m8github.com/jackc/pgproto3/v2@v2.0.22.3.3
MediumGHSA-mrww-27vc-gghvgithub.com/jackc/pgx/v4@v4.7.14.18.2
MediumDEBIAN-CVE-2019-9192glibc@2.41-12+deb13u3no fix listed
MediumALPINE-CVE-2026-9079curl@8.17.0-r18.22.0-r0
MediumDEBIAN-CVE-2026-42010gnutls28@3.8.9-33.8.9-3+deb13u4
MediumALPINE-CVE-2026-63073openssl@3.5.7-r03.5.8-r0
MediumDEBIAN-CVE-2026-63073openssl@3.5.6-1~deb13u23.5.7-1~deb13u2
MediumDEBIAN-CVE-2018-5709krb5@1.21.3-5no fix listed
MediumALPINE-CVE-2026-10536curl@8.17.0-r18.22.0-r0
MediumDLA-3559-1libssh2@1.8.0-2.11.8.0-2.1+deb10u1
MediumDEBIAN-CVE-2018-6829libgcrypt20@1.11.0-7no fix listed
MediumALPINE-CVE-2026-18924curl@8.17.0-r18.22.0-r0
MediumDEBIAN-CVE-2025-9230openssl@3.5.1-13.5.1-1+deb13u1
MediumGHSA-69ch-w2m2-3vjpgolang.org/x/text@v0.3.30.3.8
MediumALPINE-CVE-2026-11856curl@8.17.0-r18.22.0-r0
MediumALPINE-CVE-2026-8925curl@8.17.0-r18.22.0-r0
MediumALPINE-CVE-2026-18798openssl@3.5.7-r03.5.8-r0
MediumDEBIAN-CVE-2026-18798openssl@3.5.6-1~deb13u23.5.7-1~deb13u2
MediumDEBIAN-CVE-2025-9231openssl@3.5.1-13.5.1-1+deb13u1
MediumDEBIAN-CVE-2026-33845gnutls28@3.8.9-33.8.9-3+deb13u4
MediumDEBIAN-CVE-2011-3389gnutls28@3.8.9-3+deb13u4no fix listed
MediumGO-2026-4887github.com/docker/docker@v28.5.2+incompatibleno fix listed
MediumGHSA-ppp9-7jff-5vj2golang.org/x/text@v0.3.30.3.7
MediumDEBIAN-CVE-2026-42009gnutls28@3.8.9-33.8.9-3+deb13u4
MediumALPINE-CVE-2026-63076openssl@3.5.7-r03.5.8-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.23.0latest2 months ago1.23.00614891510,755

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/artifact-hub/artifact-hub.svg)](https://charts.stackradar.io/charts/artifact-hub/artifact-hub)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.