StackRadar

pulsar 1.0.8 Helm chart

cnieg

Scored 14 Sept 2026

Apache Pulsar Helm chart for Kubernetes

Version 1.0.8 4 years agodeploys tag v0.1.0 0Artifact Hub

pulsar 1.0.8 deploys 2 container images: apachepulsar/pulsar-manager and apachepulsar/pulsar. Across them, 749 findings30 critical, 59 high 15 on CISA KEV. The highest contribution is GHSA-jfh8-c2jp-5v3q in log4j-core 2.10.0, fixed in 2.12.2.

Radar Score

16,8603059324336

749 findings over 2 of 2 images measured

KEV ×15 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
apachepulsar/pulsar-managerv0.1.0214618314310,210
apachepulsar/pulsar×172.6.19131411936,650

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

260 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowDLA-3782-1util-linux@2.33.1-0.12.33.1-0.1+deb10u1
LowGHSA-m8wh-mqgf-rr8gclient-java@2.0.011.0.1
LowDLA-3586-1ncurses@6.1+20181013-2+deb10u26.1+20181013-2+deb10u4
LowDLA-3692-1curl@7.64.0-4+deb10u17.64.0-4+deb10u8
LowDSA-4782-1openldap@2.4.47+dfsg-3+deb10u22.4.47+dfsg-3+deb10u3
LowDLA-3119-1expat@2.2.6-2+deb10u12.2.6-2+deb10u5
LowDLA-3763-1curl@7.64.0-4+deb10u17.64.0-4+deb10u9
LowGHSA-h5c8-rqwp-cp95jinja2@2.103.1.3
LowDLA-3263-1libtasn1-6@4.13-34.13-3+deb10u1
LowGHSA-j26w-f9rq-mr2qjetty-servlets@9.4.10.v201805039.4.54
LowALPINE-CVE-2020-14344libx11@1.6.7-r01.6.10-r0
LowGHSA-72m5-fvvv-55m6bcprov-jdk15on@1.601.61
LowGHSA-72m5-fvvv-55m6bcprov-ext-jdk15on@1.591.61
LowGHSA-vwpg-f6gw-rjvfspring-cloud-netflix-zuul@2.0.2.RELEASE2.2.7
LowGHSA-jvf3-mfxv-jcqrpulsar-proxy@2.6.12.7.5
LowGHSA-jvf3-mfxv-jcqrpulsar-broker@2.4.12.7.5
LowGHSA-fmxf-pm6p-7xgmasync-http-client@2.7.02.15.0
LowGHSA-cphf-4846-3xx9vertx-core@3.4.14.5.24
LowDLA-3398-1curl@7.64.0-4+deb10u17.64.0-4+deb10u6
LowGHSA-2rmj-mq67-h97gspring-web@5.0.6.RELEASE5.3.38
LowGHSA-j3qw-g67q-7m64pulsar-proxy@2.6.12.7.5
LowGHSA-j3qw-g67q-7m64pulsar-broker@2.4.12.7.5
LowALPINE-CVE-2019-1547openssl@1.1.1b-r11.1.1d-r0
LowGHSA-xxqh-mfjm-7mv9netty-codec-http@4.1.24.Final4.1.133.Final
LowGHSA-c2rv-hwqm-wjpgcalcite-core@1.19.01.42.0
LowGHSA-9m3c-qcxr-9x87tomcat-embed-core@8.5.319.0.116
LowDLA-3070-1gnutls28@3.6.7-4+deb10u33.6.7-4+deb10u9
LowGHSA-h5fg-jpgr-rv9cvertx-web@3.4.14.5.22
LowDLA-3783-1expat@2.2.6-2+deb10u12.2.6-2+deb10u7
LowGHSA-fccg-mwvh-qqg4netty-handler@4.1.24.Final4.1.137.Final
LowGHSA-4cx2-fc23-5wg6bcpkix-jdk15on@1.601.79
LowGHSA-hr8g-6v94-x4m9bcprov-ext-jdk15on@1.59no fix listed
LowGHSA-hr8g-6v94-x4m9bcprov-jdk15on@1.60no fix listed
LowGHSA-775g-4xr8-78h8spring-expression@5.0.6.RELEASEno fix listed
LowGHSA-56v8-86gj-66jpspring-boot-devtools@2.0.2.RELEASEno fix listed
LowGHSA-q4f6-jm68-57wwnetty-codec-http@4.1.24.Final4.1.136.Final
LowDLA-3341-1curl@7.64.0-4+deb10u17.64.0-4+deb10u5
LowALPINE-CVE-2020-28928musl@1.1.20-r41.1.20-r6
LowDLA-3472-1libx11@2:1.6.7-12:1.6.7-1+deb10u3
LowGHSA-x83m-pf6f-pf9ghibernate-validator@6.0.9.Final6.2.0.Final
LowDLA-3153-1libksba@1.3.5-21.3.5-2+deb10u1
LowGHSA-6cqp-g7gg-8hr5netty-codec-http@4.1.24.Final4.1.136.Final
LowDLA-3740-1gnutls28@3.6.7-4+deb10u33.6.7-4+deb10u12
LowGHSA-cmxv-58fp-fm3gasync-http-client@2.7.02.14.5
LowGHSA-m4cv-j2px-7723netty-codec-http@4.1.24.Final4.1.133.Final
LowDLA-3248-1libksba@1.3.5-21.3.5-2+deb10u2
LowGHSA-hw6f-rjfj-j7j7eventlet@0.20.00.40.3
LowGHSA-34jh-p97f-mpxfurllib3@1.25.101.26.19
LowGHSA-4xh5-x5gv-qwphpip@20.2.225.3
LowGHSA-pr98-23f8-jwxvlogback-core@1.2.31.3.15

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.8latest4 years agov0.1.0305932433616,860

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cnieg/pulsar.svg)](https://charts.stackradar.io/charts/cnieg/pulsar)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.