StackRadar

node-red 1.2.2 Helm chart

cloudnativeapp

Scored 14 Sept 2026

Node-RED is flow-based programming for the Internet of Things

Version 1.2.2 5 years agoapp version 0.19.6 0Artifact Hub

node-red 1.2.2 deploys 1 container image: nodered/node-red-docker. Across them, 303 findings0 critical, 6 high 2 on CISA KEV. The highest contribution is GHSA-c4w7-xm78-47vh in y18n 4.0.0, fixed in 4.0.1.

Radar Score

4,79006119178

303 findings over 1 of 1 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
nodered/node-red-docker0.19.6-v8061191784,790

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

178 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-8x88-c5mf-7j5wtar@2.2.17.5.18
LowDLA-2481-1openldap@2.4.44+dfsg-5+deb9u22.4.44+dfsg-5+deb9u6
LowDLA-2566-1libbsd@0.8.3-10.8.3-1+deb9u1
LowGHSA-rv95-896h-c2vcexpress@4.16.44.19.2
LowGHSA-mm7p-fcc7-pg87nodemailer@1.11.07.0.7
LowDLA-2760-1nettle@3.3-1+b23.3-1+deb9u1
LowDSA-4646-1icu@57.1-6+deb9u257.1-6+deb9u4
LowDLA-2677-1libwebp@0.5.2-10.5.2-1+deb9u1
LowDLA-2596-1shadow@1:4.4-4.11:4.4-4.1+deb9u1
LowDLA-2659-1graphviz@2.38.0-172.38.0-17+deb9u1
LowDLA-2771-1krb5@1.15-1+deb9u11.15-1+deb9u3
LowGHSA-2g4f-4pwh-qvx6ajv@6.9.26.14.0
LowGHSA-p8p7-x288-28g6request@2.88.0no fix listed
LowGHSA-r6q2-hw4h-h46wtar@2.2.17.5.4
LowGHSA-2883-xcg3-v3hhjs-yaml@3.12.03.15.2
LowGHSA-5wg4-74h6-q47vbcrypt@2.0.15.0.0
LowGHSA-r292-9mhp-454mtar@2.2.17.5.21
LowDLA-3037-1libjpeg-turbo@1:1.5.1-21:1.5.1-2+deb9u2
LowDLA-2777-1tiff@4.0.8-2+deb9u44.0.8-2+deb9u7
LowDLA-2672-1imagemagick@8:6.9.7.4+dfsg-11+deb9u68:6.9.7.4+dfsg-11+deb9u13
LowGHSA-w5hq-g745-h8pquuid@3.3.211.1.1
LowGHSA-gxpj-cx7g-858cdebug@3.2.63.2.7
LowDLA-2425-1openldap@2.4.44+dfsg-5+deb9u22.4.44+dfsg-5+deb9u5
LowDSA-4492-1postgresql-9.6@9.6.10-0+deb9u19.6.15-0+deb9u1
LowGHSA-9ppj-qmqm-q256tar@2.2.17.5.11
LowGHSA-mpwj-fcr6-x34cyarn@1.12.31.22.13
LowDLA-2285-1librsvg@2.40.16-1+b12.40.21-0+deb9u1
LowDSA-4393-1systemd@232-25+deb9u8232-25+deb9u9
LowDLA-2550-1openjpeg2@2.1.2-1.1+deb9u22.1.2-1.1+deb9u6
LowDLA-2662-1postgresql-9.6@9.6.10-0+deb9u19.6.22-0+deb9u1
LowDLA-2669-1libxml2@2.9.4+dfsg1-2.2+deb9u22.9.4+dfsg1-2.2+deb9u5
LowDLA-2694-1tiff@4.0.8-2+deb9u44.0.8-2+deb9u6
LowGHSA-wc9g-mqfw-jrwmmulter@1.4.12.3.0
LowDLA-2817-1postgresql-9.6@9.6.10-0+deb9u19.6.24-0+deb9u1
LowDLA-3007-1imagemagick@8:6.9.7.4+dfsg-11+deb9u68:6.9.7.4+dfsg-11+deb9u14
LowDSA-4550-1file@1:5.30-1+deb9u21:5.30-1+deb9u3
LowDLA-2701-1openexr@2.2.0-11+b12.2.0-11+deb9u3
LowGHSA-f886-m6hf-6m8vbrace-expansion@1.1.111.1.13
LowGHSA-535w-7cp7-47q4multer@1.4.12.3.0
LowGHSA-72gw-mp4g-v24jmulter@1.4.12.2.0
LowGHSA-v923-w3x8-wh69passport@0.4.00.6.0
LowDLA-2732-1openexr@2.2.0-11+b12.2.0-11+deb9u4
LowDLA-2975-1openjpeg2@2.1.2-1.1+deb9u22.1.2-1.1+deb9u7
LowDLA-2897-1apr@1.5.2-51.5.2-5+deb9u1
LowGHSA-83g3-92jg-28cxtar@2.2.17.5.8
LowGHSA-8w65-xjc5-9w79node-red@0.19.60.20.8
LowGHSA-w8wr-v893-vjvptar@2.2.17.5.18
LowDLA-2691-1libgcrypt20@1.7.6-2+deb9u31.7.6-2+deb9u4
LowGHSA-p6gq-j5cr-w38fnodemailer@1.11.09.0.1
LowDLA-2602-1imagemagick@8:6.9.7.4+dfsg-11+deb9u68:6.9.7.4+dfsg-11+deb9u12

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.2.2latest5 years ago0.19.6061191784,790

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cloudnativeapp/node-red.svg)](https://charts.stackradar.io/charts/cloudnativeapp/node-red)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.