thingsboard Helm chart
ceticScored 14 Sept 2026
A Helm chart for Kubernetes
Latest 0.1.2 2 years agodeploys tag 3.8.14-debian-10-r24 2Artifact Hub
thingsboard 0.1.2 deploys 2 container images: bitnami/rabbitmq and thingsboard/tb-postgres. Across the 1 measured, 500 findings — 0 critical, 1 high. The highest contribution is DEBIAN-CVE-2025-15467 in openssl 3.0.17-1~deb12u3, fixed in 3.0.18-1~deb12u2.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| bitnami/ | 3.8.14-debian-10-r24 | — | unmeasured |
| thingsboard/ | latest | 0177421 | 5,235 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DEBIAN-CVE-2026-70907 | openjdk-17 | 17.0.20.1+1-1~deb12u1 |
| Low | DEBIAN-CVE-2026-45446 | openssl | 3.0.20-1~deb12u2 |
| Low | GHSA-25qh-j22f-pwp8 | logback-core | 1.5.19 |
| Low | DEBIAN-CVE-2026-86138 | libxml2 | no fix listed |
| Low | DEBIAN-CVE-2026-86143 | libxml2 | no fix listed |
| Low | DEBIAN-CVE-2026-56412 | expat | 2.5.0-1+deb12u3 |
| Low | DEBIAN-CVE-2025-58436 | cups | no fix listed |
| Low | DEBIAN-CVE-2026-40225 | systemd | 252.39-1~deb12u2 |
| Low | DEBIAN-CVE-2026-50219 | expat | 2.5.0-1+deb12u3 |
| Low | DEBIAN-CVE-2026-56409 | expat | 2.5.0-1+deb12u3 |
| Low | DEBIAN-CVE-2026-39314 | cups | no fix listed |
| Low | DEBIAN-CVE-2026-27171 | zlib | no fix listed |
| Low | DEBIAN-CVE-2017-14159 | openldap | no fix listed |
| Low | DEBIAN-CVE-2026-34990 | cups | no fix listed |
| Low | DEBIAN-CVE-2025-29088 | sqlite3 | no fix listed |
| Low | DEBIAN-CVE-2026-50813 | sqlite3 | no fix listed |
| Low | DEBIAN-CVE-2026-32777 | expat | no fix listed |
| Low | DEBIAN-CVE-2017-18018 | coreutils | no fix listed |
| Low | DEBIAN-CVE-2026-86139 | libxml2 | no fix listed |
| Low | DEBIAN-CVE-2026-13757 | p11-kit | no fix listed |
| Low | GHSA-hvcg-qmg6-jm4c | netty-codec-http | 4.1.135.Final |
| Low | DEBIAN-CVE-2026-11850 | krb5 | no fix listed |
| Low | DEBIAN-CVE-2026-56132 | expat | no fix listed |
| Low | DEBIAN-CVE-2026-6767 | nss | 2:3.87.1-1+deb12u3 |
| Low | DEBIAN-CVE-2025-66382 | expat | no fix listed |
| Low | DEBIAN-CVE-2026-34933 | avahi | no fix listed |
| Low | DEBIAN-CVE-2026-15146 | wget | no fix listed |
| Low | DEBIAN-CVE-2026-15588 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2026-56392 | coreutils | no fix listed |
| Low | DEBIAN-CVE-2026-54370 | acl | no fix listed |
| Low | DEBIAN-CVE-2005-2541 | tar | no fix listed |
| Low | GHSA-957g-f97v-vppc | spring-webmvc | 6.2.19 |
| Low | DEBIAN-CVE-2026-15534 | perl | no fix listed |
| Low | GHSA-cvc6-q2cp-2xhw | spring-security-oauth2-jose | no fix listed |
| Low | DEBIAN-CVE-2025-59529 | avahi | no fix listed |
| Low | DEBIAN-CVE-2026-56391 | coreutils | no fix listed |
| Low | DEBIAN-CVE-2025-10911 | libxslt | no fix listed |
| Low | DEBIAN-CVE-2026-32778 | expat | no fix listed |
| Low | DEBIAN-CVE-2026-86144 | libxml2 | no fix listed |
| Low | GHSA-cjpg-rgq5-fr37 | spring-webmvc | 6.2.19 |
| Low | GHSA-cjpg-rgq5-fr37 | spring-webflux | 6.2.19 |
| Low | DEBIAN-CVE-2024-10041 | pam | no fix listed |
| Low | GHSA-mhm7-754m-9p8w | jackson-databind | 2.18.9 |
| Low | DEBIAN-CVE-2026-32776 | expat | no fix listed |
| Low | DEBIAN-CVE-2026-50812 | sqlite3 | no fix listed |
| Low | DEBIAN-CVE-2025-68276 | avahi | no fix listed |
| Low | DEBIAN-CVE-2025-9714 | libxml2 | 2.9.14+dfsg-1.3~deb12u5 |
| Low | DEBIAN-CVE-2026-87875 | cups | no fix listed |
| Low | DEBIAN-CVE-2026-18938 | p11-kit | no fix listed |
| Low | DEBIAN-CVE-2026-0989 | libxml2 | 2.9.14+dfsg-1.3~deb12u6 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.1.2latest | 2 years ago | 3.8.14-debian-10-r24 | 0177421 | 5,235 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.