StackRadar

galaxy 6.8.4 Helm chart

cloudve

Scored 15 Sept 2026

Chart for Galaxy, an open, web-based platform for accessible, reproducible, and transparent computational biomedical research.

Version 6.8.4 17 days agoapp version 26.1.1 0Artifact Hub

galaxy 6.8.4 deploys 3 container images: quay.io/galaxyproject/galaxy-min, library/nginx and tusproject/tusd. Across them, 516 findings0 critical, 9 high 5 on CISA KEV. The highest contribution is ALPINE-CVE-2024-6119 in openssl 3.1.2-r0, fixed in 3.1.7-r0.

Radar Score

5,5520956450

516 findings over 3 of 3 images measured

KEV ×5 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
quay.io/galaxyproject/galaxy-min×626.1.100262712,951
library/nginx1.22.0041059967
tusproject/tusdv1.13.005201201,634

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

516 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2025-53906vim@2:9.1.1230-2no fix listed
LowGO-2026-4977stdlib@go1.21.01.25.10
LowGO-2024-2610stdlib@go1.21.01.21.8
LowDLA-4315-1tiff@4.2.0-1+deb11u14.2.0-1+deb11u7
LowDLA-4259-1systemd@247.3-7+deb11u1247.3-7+deb11u7
LowDEBIAN-CVE-2026-16599wget@1.25.0-2no fix listed
LowGO-2026-4986stdlib@go1.21.01.25.10
LowGO-2026-4918stdlib@go1.21.01.25.10
LowGO-2026-4918golang.org/x/net@v0.14.00.53.0
LowGO-2026-4337stdlib@go1.21.01.24.13
LowDEBIAN-CVE-2026-6390nano@8.4-1+deb13u1no fix listed
LowDEBIAN-CVE-2026-28419vim@2:9.1.1230-2no fix listed
LowDLA-3951-1curl@7.74.0-1.3+deb11u37.74.0-1.3+deb11u14
LowGO-2026-4601stdlib@go1.21.01.25.8
LowDLA-3875-1gnutls28@3.7.1-5+deb11u23.7.1-5+deb11u6
LowDEBIAN-CVE-2026-19499glibc@2.41-12+deb13u3no fix listed
LowDEBIAN-CVE-2026-78410util-linux@2.41-5no fix listed
LowDEBIAN-CVE-2026-35177vim@2:9.1.1230-2no fix listed
LowDEBIAN-CVE-2026-89161pcre2@10.46-1~deb13u110.46-1~deb13u2
LowGO-2026-5026stdlib@go1.21.01.25.13
LowGO-2026-5026golang.org/x/net@v0.14.00.55.0
LowDEBIAN-CVE-2025-14104util-linux@2.41-52.41.3-1
LowGO-2025-3420stdlib@go1.21.01.22.11
LowGO-2026-4342stdlib@go1.21.01.24.12
LowGO-2024-2598stdlib@go1.21.01.21.8
LowGO-2025-3751stdlib@go1.21.01.23.10
LowDEBIAN-CVE-2026-78409util-linux@2.41-5no fix listed
LowDLA-4492-1gnutls28@3.7.1-5+deb11u23.7.1-5+deb11u9
LowALPINE-CVE-2024-13176openssl@3.1.2-r03.1.8-r0
LowGHSA-2v4p-qf9q-27wjgoogle.golang.org/grpc@v1.57.01.82.2
LowGHSA-537c-gmf6-5ccfcryptography@48.0.048.0.1
LowGHSA-m425-mq94-257ggoogle.golang.org/grpc@v1.57.01.57.1
LowDEBIAN-CVE-2026-45130vim@2:9.1.1230-2no fix listed
LowDSA-5517-1libx11@2:1.7.2-12:1.7.2-1+deb11u2
LowDLA-4146-1libxml2@2.9.10+dfsg-6.7+deb11u22.9.10+dfsg-6.7+deb11u7
LowGO-2025-4116golang.org/x/crypto@v0.12.00.43.0
LowGO-2026-4870stdlib@go1.21.01.25.9
LowGO-2025-4009stdlib@go1.21.01.24.8
LowGO-2026-4947stdlib@go1.21.01.25.9
LowDLA-4176-1openssl@1.1.1n-0+deb11u31.1.1w-0+deb11u3
LowGO-2025-4006stdlib@go1.21.01.24.8
LowDEBIAN-CVE-2026-73074vim@2:9.1.1230-2no fix listed
LowDLA-3930-1libsepol@3.1-13.1-1+deb11u1
LowGO-2026-5037stdlib@go1.21.01.25.11
LowGO-2026-4971stdlib@go1.21.01.25.10
LowDEBIAN-CVE-2026-28418vim@2:9.1.1230-2no fix listed
LowGO-2026-5972stdlib@go1.21.01.25.13
LowGO-2026-6088stdlib@go1.21.01.25.13
LowGO-2026-6089stdlib@go1.21.01.25.13
LowGO-2026-6090stdlib@go1.21.01.25.13

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
6.8.6latest4 days ago26.1.109564505,552
6.8.57 days ago26.1.109564505,552
6.8.417 days ago26.1.109564505,552

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cloudve/galaxy.svg)](https://charts.stackradar.io/charts/cloudve/galaxy)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.