StackRadar

robot-shop Helm chart

cloud-native-toolkit

Scored 14 Sept 2026

Sample micoservices application

Latest 1.1.1 4 years agoApp version not verified against the render 0Artifact Hub

robot-shop 1.1.1 deploys 12 container images: robotshop/rs-cart, robotshop/rs-catalogue, robotshop/rs-dispatch, robotshop/rs-mongodb and 8 more. Across them, 1,885 findings14 critical, 61 high 24 on CISA KEV. The highest contribution is GHSA-36p3-wjmg-h94x in spring-webmvc 5.2.8.RELEASE, fixed in 5.2.20.RELEASE.

Radar Score

29,55514615551,255

1,885 findings over 12 of 12 images measured

KEV ×24 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

12 images
ImageTagVulnerabilitiesRadar Score
robotshop/rs-cartlatest0243731,950
robotshop/rs-cataloguelatest0242731,931
robotshop/rs-dispatchlatest03301842,584
robotshop/rs-mongodblatest7171373707,786
robotshop/rs-mysql-dblatest001229636
robotshop/rs-paymentlatest06901783,986
library/rabbitmq3.7-management-alpine192941,438
robotshop/rs-ratingslatest0427751,648
robotshop/rs-shippinglatest614731234,190
robotshop/rs-userlatest0243731,950
robotshop/rs-weblatest0220531,151
library/redis4.0.600920305

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

710 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowDLA-3513-1tiff@4.1.0+git191117-2~deb10u24.1.0+git191117-2~deb10u8
LowDSA-5567-1tiff@4.2.0-14.2.0-1+deb11u5
LowDLA-4432-1curl@7.74.0-1.3+b17.74.0-1.3+deb11u16
LowUBUNTU-CVE-2026-7017perl@5.30.0-9ubuntu0.2no fix listed
LowDLA-4064-1libxml2@2.9.10+dfsg-6.72.9.10+dfsg-6.7+deb11u6
LowGO-2022-0525stdlib@go1.171.17.12
LowGO-2022-0520stdlib@go1.171.17.12
LowMAL-2022-4933npm-cli-docs@0.1.0no fix listed
LowDLA-2932-1tiff@4.0.8-2+deb9u64.0.8-2+deb9u8
LowUBUNTU-CVE-2025-0395glibc@2.31-0ubuntu9.22.31-0ubuntu9.17
LowUBUNTU-CVE-2023-4039gcc-10@10.3.0-1ubuntu1~20.0410.5.0-1ubuntu1~20.04.1+esm1
LowDLA-3850-1glibc@2.28-102.28-10+deb10u4
LowDSA-5678-1glibc@2.31-132.31-13+deb11u10
LowUBUNTU-CVE-2026-76642util-linux@2.34-0.1ubuntu9.1no fix listed
LowDLA-2210-1apt@1.0.9.8.41.0.9.8.6
LowGHSA-j5w8-q4qc-rx2xgolang.org/x/crypto@v0.0.0-20200302210943-78000ba7a0730.45.0
LowUBUNTU-CVE-2026-11822sqlite3@3.31.1-4ubuntu0.2no fix listed
LowUBUNTU-CVE-2026-11824sqlite3@3.31.1-4ubuntu0.2no fix listed
LowDLA-4267-1gnutls28@3.7.1-53.7.1-5+deb11u8
LowDLA-4074-1mariadb-10.5@1:10.5.11-11:10.5.28-0+deb11u1
LowUBUNTU-CVE-2025-4598systemd@245.4-4ubuntu3.11245.4-4ubuntu3.24+esm1
LowDLA-3459-1libxpm@1:3.5.12-11:3.5.12-1+deb10u1
LowDLA-3881-1aom@1.0.0.errata1-31.0.0.errata1-3+deb11u2
LowDLA-3962-1glib2.0@2.66.8-12.66.8-1+deb11u5
LowPYSEC-2026-3721pip@21.2.426.2
LowGO-2023-2375stdlib@go1.171.20.0
LowUBUNTU-CVE-2025-15079curl@7.68.0-1ubuntu2.67.68.0-1ubuntu2.25+esm2
LowGO-2023-1569stdlib@go1.171.19.6
LowDLA-3107-1sqlite3@3.27.2-3+deb10u13.27.2-3+deb10u2
LowDLA-4309-1libxslt@1.1.34-41.1.34-4+deb11u3
LowGHSA-mq26-g339-26xfpip@21.2.423.3
LowGHSA-cm22-4g7w-348pserve-static@1.14.11.16.0
LowGHSA-cpwx-vrp4-4pq7jinja2@3.0.13.1.6
LowDLA-2784-1icu@57.1-6+deb9u457.1-6+deb9u5
LowGO-2023-2382stdlib@go1.171.20.12
LowUBUNTU-CVE-2026-6429curl@7.68.0-1ubuntu2.6no fix listed
LowDLA-1762-1systemd@215-17+deb8u7215-17+deb8u12
LowGO-2022-1143stdlib@go1.171.18.9
LowGHSA-qpw4-5x99-6vjpgolang.org/x/crypto@v0.0.0-20200302210943-78000ba7a0730.52.0
LowUBUNTU-CVE-2024-22365pam@1.3.1-5ubuntu4.21.3.1-5ubuntu4.7
LowDSA-5401-1postgresql-13@13.3-113.11-0+deb11u1
LowUBUNTU-CVE-2026-22796openssl@1.1.1f-1ubuntu2.81.1.1f-1ubuntu2.24+esm2
LowGHSA-f6x5-jh6r-wrfvgolang.org/x/crypto@v0.0.0-20200302210943-78000ba7a0730.45.0
LowGHSA-72pg-x5f8-j25jspring-webmvc@5.2.8.RELEASEno fix listed
LowGHSA-gvwx-54wh-qm9jtar@4.4.157.5.17
LowGHSA-78mq-xcr3-xm33golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a0730.52.0
LowGO-2024-2599stdlib@go1.171.21.8
LowDLA-4344-1gdk-pixbuf@2.42.2+dfsg-12.42.2+dfsg-1+deb11u4
LowGO-2022-1038stdlib@go1.171.18.7
LowDSA-5357-1git@1:2.30.2-11:2.30.2-1+deb11u2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.1.1latest4 years ago14615551,25529,555

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cloud-native-toolkit/robot-shop.svg)](https://charts.stackradar.io/charts/cloud-native-toolkit/robot-shop)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.