StackRadar

robot-shop Helm chart

cloud-native-toolkit

Scored 14 Sept 2026

Sample micoservices application

Latest 1.1.1 4 years agoApp version not verified against the render 0Artifact Hub

robot-shop 1.1.1 deploys 12 container images: robotshop/rs-cart, robotshop/rs-catalogue, robotshop/rs-dispatch, robotshop/rs-mongodb and 8 more. Across them, 1,885 findings14 critical, 61 high 24 on CISA KEV. The highest contribution is GHSA-36p3-wjmg-h94x in spring-webmvc 5.2.8.RELEASE, fixed in 5.2.20.RELEASE.

Radar Score

29,55514615551,255

1,885 findings over 12 of 12 images measured

KEV ×24 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

12 images
ImageTagVulnerabilitiesRadar Score
robotshop/rs-cartlatest0243731,950
robotshop/rs-cataloguelatest0242731,931
robotshop/rs-dispatchlatest03301842,584
robotshop/rs-mongodblatest7171373707,786
robotshop/rs-mysql-dblatest001229636
robotshop/rs-paymentlatest06901783,986
library/rabbitmq3.7-management-alpine192941,438
robotshop/rs-ratingslatest0427751,648
robotshop/rs-shippinglatest614731234,190
robotshop/rs-userlatest0243731,950
robotshop/rs-weblatest0220531,151
library/redis4.0.600920305

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

710 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-gmj6-6f8f-6699jinja2@3.0.13.1.5
LowUBUNTU-CVE-2025-6020pam@1.3.1-5ubuntu4.2no fix listed
LowUBUNTU-CVE-2023-27538curl@7.68.0-1ubuntu2.67.68.0-1ubuntu2.18
LowGHSA-hhhw-99gj-p3c3snakeyaml@1.261.31
LowUBUNTU-CVE-2023-7104sqlite3@3.31.1-4ubuntu0.23.31.1-4ubuntu0.6
LowUBUNTU-CVE-2022-45142heimdal@7.7.0+dfsg-1ubuntu17.7.0+dfsg-1ubuntu1.4
LowDLA-3682-1ncurses@6.1+20181013-2+deb10u26.1+20181013-2+deb10u5
LowGO-2021-0239stdlib@go1.16.31.15.13
LowUBUNTU-CVE-2026-86145pcre2@10.34-7no fix listed
LowGHSA-qv9r-c865-cp47log4j-api@2.13.32.25.5
LowGO-2021-0347stdlib@go1.171.16.15
LowUBUNTU-CVE-2024-8096curl@7.68.0-1ubuntu2.67.68.0-1ubuntu2.24
LowGO-2021-0245stdlib@go1.16.31.15.15
LowGHSA-q4h4-gmj2-qvw2golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a0730.52.0
LowGHSA-23c5-xmqv-rm74minimatch@3.0.43.1.4
LowGHSA-mgvc-8q2h-5pgcspring-boot-starter-actuator@2.3.3.RELEASEno fix listed
LowGO-2021-0319stdlib@go1.171.16.14
LowUBUNTU-CVE-2023-47039perl@5.30.0-9ubuntu0.2no fix listed
LowGHSA-5mp6-jrq3-r938tomcat-embed-core@9.0.379.0.118
LowGHSA-w879-237q-wc7rgolang.org/x/crypto@v0.0.0-20200302210943-78000ba7a0730.52.0
LowGHSA-mh99-v99m-4gvgbrace-expansion@1.1.111.1.17
LowUBUNTU-CVE-2025-15281glibc@2.31-0ubuntu9.22.31-0ubuntu9.18+esm1
LowUBUNTU-CVE-2025-6297dpkg@1.19.7ubuntu3no fix listed
LowGHSA-f9vj-2wh5-fj8jwerkzeug@2.0.13.0.6
LowDLA-1639-1systemd@215-17+deb8u7215-17+deb8u9
LowUBUNTU-CVE-2026-42011gnutls28@3.6.13-2ubuntu1.63.6.13-2ubuntu1.12+esm3
LowUBUNTU-CVE-2024-12243gnutls28@3.6.13-2ubuntu1.63.6.13-2ubuntu1.12
LowUBUNTU-CVE-2022-41916heimdal@7.7.0+dfsg-1ubuntu17.7.0+dfsg-1ubuntu1.2
LowUBUNTU-CVE-2026-9538perl@5.30.0-9ubuntu0.2no fix listed
LowGO-2022-0493stdlib@go1.171.17.10
LowGHSA-x4m4-345f-5h5gtomcat-embed-core@9.0.379.0.117
LowGHSA-gfwj-fwqj-fp3vspring-web@5.2.8.RELEASE5.2.15
LowUBUNTU-CVE-2025-6395gnutls28@3.6.13-2ubuntu1.63.6.13-2ubuntu1.12+esm1
LowUBUNTU-CVE-2025-24528krb5@1.17-6ubuntu4.11.17-6ubuntu4.9
LowGHSA-8x88-c5mf-7j5wtar@4.4.157.5.18
LowGHSA-jjfh-589g-3hjxspring-boot-actuator@2.3.3.RELEASE2.7.18
LowGO-2021-0317stdlib@go1.171.16.14
LowUBUNTU-CVE-2026-85091zlib@1:1.2.11.dfsg-2ubuntu1.2no fix listed
LowGHSA-rv95-896h-c2vcexpress@4.17.14.19.2
LowDSA-5200-1libtirpc@1.3.1-11.3.1-1+deb11u1
LowGHSA-fpj8-gq4v-p354tomcat-embed-core@9.0.379.0.113
LowDSA-5628-1imagemagick@8:6.9.11.60+dfsg-1.38:6.9.11.60+dfsg-1.3+deb11u3
LowGO-2023-2185stdlib@go1.171.20.11
LowUBUNTU-CVE-2026-42497perl@5.30.0-9ubuntu0.2no fix listed
LowUBUNTU-CVE-2026-41992gzip@1.10-0ubuntu4no fix listed
LowUBUNTU-CVE-2023-7008systemd@245.4-4ubuntu3.11no fix listed
LowGHSA-hgrr-935x-pq79tomcat-embed-core@9.0.379.0.110
LowDLA-2760-1nettle@3.3-1+b23.3-1+deb9u1
LowALPINE-CVE-2020-15358sqlite@3.32.1-r03.32.1-r1
LowUBUNTU-CVE-2020-29562glibc@2.31-0ubuntu9.22.31-0ubuntu9.7

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.1.1latest4 years ago14615551,25529,555

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cloud-native-toolkit/robot-shop.svg)](https://charts.stackradar.io/charts/cloud-native-toolkit/robot-shop)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.