self-host 2.5.0 Helm chart
bitwardenNot scored yet
A Helm chart for deploying a Bitwarden instance on Kubernetes
Version 2.5.0 todayapp version 2026.9.0 1Artifact Hub
self-host 2.5.0 deploys 11 container images: ghcr.io/bitwarden/admin, ghcr.io/bitwarden/api, ghcr.io/bitwarden/attachments, ghcr.io/bitwarden/events and 7 more. The highest contribution is UBUNTU-CVE-2026-45447 in openssl 3.0.13-0ubuntu3.9, fixed in 3.0.13-0ubuntu3.11.
Radar Score
Not yet scored
The daily scoring run has not folded the 11 images into a score yet.
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | 2026.9.0 | 0009 | 61 |
| ghcr.io/ | 2026.9.0 | 0009 | 61 |
| ghcr.io/ | 2026.9.0 | 0009 | 61 |
| ghcr.io/ | 2026.9.0 | 0009 | 61 |
| ghcr.io/ | 2026.9.0 | 0009 | 61 |
| ghcr.io/ | 2026.9.0 | 0009 | 61 |
| ghcr.io/ | 2026.9.0 | 0009 | 61 |
| ghcr.io/ | 2026.9.0 | 0009 | 61 |
| ghcr.io/ | 2026.9.0 | 00613 | 224 |
| mcr.microsoft.com/ | 2025-CU5-ubuntu-24.04 | 0039296 | 3,101 |
| ghcr.io/ | 2026.9.0 | 0000 | 0 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | UBUNTU-CVE-2026-45447 | openssl | 3.0.13-0ubuntu3.11 |
| Medium | UBUNTU-CVE-2026-5121 | libarchive | 3.7.2-2ubuntu0.7 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | UBUNTU-CVE-2023-3326 | sssd | no fix listed |
| Medium | UBUNTU-CVE-2026-8925 | curl | 8.5.0-2ubuntu10.10 |
| Medium | UBUNTU-CVE-2016-20013 | sssd | no fix listed |
| Medium | UBUNTU-CVE-2016-20013 | glibc | no fix listed |
| Medium | UBUNTU-CVE-2026-34182 | openssl | 3.0.13-0ubuntu3.11 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | UBUNTU-CVE-2026-63076 | openssl | 3.0.13-0ubuntu3.15 |
| Medium | UBUNTU-CVE-2026-5450 | glibc | 2.39-0ubuntu8.8 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | UBUNTU-CVE-2026-11856 | curl | 8.5.0-2ubuntu10.12 |
| Medium | UBUNTU-CVE-2026-7210 | python3.12 | no fix listed |
| Medium | UBUNTU-CVE-2026-10536 | curl | 8.5.0-2ubuntu10.11 |
| Medium | UBUNTU-CVE-2026-14474 | sssd | no fix listed |
| Medium | UBUNTU-CVE-2025-59375 | expat | 2.6.1-2ubuntu0.5 |
| Medium | ALPINE-CVE-2026-54874 | openssl | 3.5.8-r0 |
| Medium | UBUNTU-CVE-2026-34180 | openssl | 3.0.13-0ubuntu3.11 |
| Medium | UBUNTU-CVE-2026-54874 | openssl | 3.0.13-0ubuntu3.15 |
| Medium | UBUNTU-CVE-2025-11561 | sssd | no fix listed |
| Medium | UBUNTU-CVE-2026-57433 | perl | 5.38.2-3.2ubuntu0.4 |
| Medium | UBUNTU-CVE-2026-5260 | gnutls28 | 3.8.3-1.1ubuntu3.6 |
| Medium | UBUNTU-CVE-2026-4224 | python3.12 | 3.12.3-1ubuntu0.15 |
| Medium | UBUNTU-CVE-2026-8924 | curl | 8.5.0-2ubuntu10.10 |
| Medium | UBUNTU-CVE-2026-42009 | gnutls28 | 3.8.3-1.1ubuntu3.6 |
| Medium | UBUNTU-CVE-2026-33846 | gnutls28 | 3.8.3-1.1ubuntu3.6 |
| Medium | UBUNTU-CVE-2026-8376 | perl | 5.38.2-3.2ubuntu0.3 |
| Medium | UBUNTU-CVE-2026-4424 | libarchive | 3.7.2-2ubuntu0.7 |
| Medium | UBUNTU-CVE-2026-18924 | curl | 8.5.0-2ubuntu10.15 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Medium | UBUNTU-CVE-2026-63072 | openssl | 3.0.13-0ubuntu3.15 |
| Medium | UBUNTU-CVE-2025-69720 | ncurses | 6.4+20240113-1ubuntu2.1 |
| Medium | UBUNTU-CVE-2026-58016 | glib2.0 | 2.80.0-6ubuntu3.9 |
| Medium | UBUNTU-CVE-2026-9076 | openssl | 3.0.13-0ubuntu3.11 |
| Medium | UBUNTU-CVE-2026-6100 | python3.12 | 3.12.3-1ubuntu0.15 |
| Medium | UBUNTU-CVE-2026-11972 | python3.12 | no fix listed |
| Medium | UBUNTU-CVE-2026-42496 | perl | 5.38.2-3.2ubuntu0.3 |
| Medium | UBUNTU-CVE-2026-8927 | curl | 8.5.0-2ubuntu10.10 |
| Medium | UBUNTU-CVE-2026-33845 | gnutls28 | 3.8.3-1.1ubuntu3.6 |
| Medium | UBUNTU-CVE-2026-7383 | openssl | 3.0.13-0ubuntu3.11 |
| Medium | UBUNTU-CVE-2026-11940 | python3.12 | no fix listed |
| Medium | UBUNTU-CVE-2026-14476 | sssd | no fix listed |
| Medium | UBUNTU-CVE-2026-42010 | gnutls28 | 3.8.3-1.1ubuntu3.6 |
| Low | UBUNTU-CVE-2026-6653 | libxml2 | 2.9.14+dfsg-1.3ubuntu3.8 |
| Low | UBUNTU-CVE-2026-9669 | python3.12 | 3.12.3-1ubuntu0.15 |
| Low | ALPINE-CVE-2026-63075 | openssl | 3.5.8-r0 |
| Low | UBUNTU-CVE-2026-13221 | perl | 5.38.2-3.2ubuntu0.4 |
| Low | UBUNTU-CVE-2026-66046 | expat | 2.6.1-2ubuntu0.6 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.5.0latest | today | 2026.9.0 | — | — |
| 2.4.2 | 13 days ago | 2026.9.0 | 0045381 | 3,813 |
| 2.4.1 | 15 days ago | 2026.8.2 | 0089454 | 5,524 |
| 2.4.0 | 1 month ago | 2026.8.0 | 0089454 | 5,531 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.