StackRadar

pulsar Helm chart

cnieg

Scored 14 Sept 2026

Apache Pulsar Helm chart for Kubernetes

Latest 1.0.8 4 years agodeploys tag v0.1.0 0Artifact Hub

pulsar 1.0.8 deploys 2 container images: apachepulsar/pulsar-manager and apachepulsar/pulsar. Across them, 749 findings30 critical, 59 high 15 on CISA KEV. The highest contribution is GHSA-jfh8-c2jp-5v3q in log4j-core 2.10.0, fixed in 2.12.2.

Radar Score

16,8603059324336

749 findings over 2 of 2 images measured

KEV ×15 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
apachepulsar/pulsar-managerv0.1.0214618314310,210
apachepulsar/pulsar×172.6.19131411936,650

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

260 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-gcjf-9mgh-3p7gnetty-codec-http@4.1.24.Final4.1.136.Final
LowGHSA-v8h7-rr48-vmmvnetty-codec-http@4.1.24.Final4.1.133.Final
LowGHSA-9cmq-m9j5-mvwwspring-expression@5.0.6.RELEASE5.3.39
LowGHSA-563q-j3cm-6jxmnetty-codec-http2@4.1.24.Final4.1.135.Final
LowGHSA-5x3r-wrvg-rp6qnetty-codec-http2@4.1.24.Final4.1.135.Final
LowGHSA-3gh6-v5v9-6v9jjetty-servlets@9.4.10.v201805039.4.52
LowGHSA-xpw8-rcwv-8f8pnetty-codec-http2@4.1.24.Final4.1.100.Final
LowGHSA-m6cp-vxjx-65j6jetty-server@9.4.10.v201805039.4.41
LowGHSA-7g45-4rm6-3mm3guava@11.0.232.0.0-android
LowDLA-3602-1libx11@2:1.6.7-12:1.6.7-1+deb10u4
LowGHSA-g4mx-q9vg-27p4urllib3@1.25.101.26.18
LowGHSA-25qh-j22f-pwp8logback-core@1.2.31.3.16
LowDLA-3110-1glib2.0@2.58.3-2+deb10u22.58.3-2+deb10u4
LowGHSA-5mg8-w23w-74h3guava@11.0.232.0.0-android
LowGHSA-hvcg-qmg6-jm4cnetty-codec-http@4.1.24.Final4.1.135.Final
LowGHSA-45p5-v273-3qqrvertx-web@3.4.14.5.22
LowGHSA-957g-f97v-vppcspring-webmvc@5.0.6.RELEASEno fix listed
LowPYSEC-2026-2275requests@2.24.02.33.0
LowGHSA-cjpg-rgq5-fr37spring-webmvc@5.0.6.RELEASEno fix listed
LowDSA-4850-1libzstd@1.3.8+dfsg-31.3.8+dfsg-3+deb10u1
LowDLA-3474-1systemd@241-7~deb10u3241-7~deb10u10
LowGHSA-wf8f-6423-gfxgjackson-core@2.9.52.13.0
LowGHSA-cj7v-27pg-wf7qjetty-http@9.4.10.v201805039.4.47
LowDSA-4808-1apt@1.8.21.8.2.2
LowDLA-3603-1libxpm@1:3.5.12-11:3.5.12-1+deb10u2
LowDSA-4859-1libzstd@1.3.8+dfsg-31.3.8+dfsg-3+deb10u2
LowDLA-3771-1python2.7@2.7.16-2+deb10u12.7.16-2+deb10u4
LowDLA-3772-1python3.7@3.7.3-2+deb10u23.7.3-2+deb10u7
LowGHSA-m452-q8c9-rg2fasync-http-client@2.7.02.16.0
LowGHSA-jp4c-xjxw-mgf9pip@20.2.226.1
LowDLA-3755-1tar@1.30+dfsg-61.30+dfsg-6+deb10u1
LowGHSA-p26g-97m4-6q7cjetty-server@9.4.10.v201805039.4.51.v20230217
LowGHSA-9m89-8frq-c98ctomcat-embed-core@8.5.319.0.118
LowGHSA-659m-px2c-25wjspring-core@5.0.6.RELEASEno fix listed
LowDLA-3579-1elfutils@0.176-1.10.176-1.1+deb10u1
LowGHSA-58qw-9mgm-455vpip@20.2.226.1
LowGHSA-4wp7-92pw-q264spring-context@5.0.6.RELEASEno fix listed
LowGHSA-h3qp-gqrc-q736spring-webmvc@5.0.6.RELEASEno fix listed
LowGHSA-9f52-rjqv-25qvspring-expression@5.0.6.RELEASEno fix listed
LowGHSA-w573-9ffj-6ff9netty-transport-native-epoll@4.1.24.Final4.1.135.Final
LowGHSA-w573-9ffj-6ff9netty-transport-native-kqueue@4.1.48.Final4.1.135.Final
LowGHSA-wjpw-4j6x-6rwhjetty-http@9.4.10.v20180503no fix listed
LowGHSA-wg35-8jpf-2xv3spring-webmvc@5.0.6.RELEASEno fix listed
LowDLA-3112-1bzip2@1.0.6-9.2~deb10u11.0.6-9.2~deb10u2
LowDLA-3134-1tzdata@2019c-0+deb10u12021a-0+deb10u7
LowDLA-3161-1tzdata@2019c-0+deb10u12021a-0+deb10u8
LowDLA-3366-1tzdata@2019c-0+deb10u12021a-0+deb10u10
LowDLA-3412-1tzdata@2019c-0+deb10u12021a-0+deb10u11
LowDLA-3482-1debian-archive-keyring@2019.12019.1+deb10u2
LowDLA-3684-1tzdata@2019c-0+deb10u12021a-0+deb10u12

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.8latest4 years agov0.1.0305932433616,860

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cnieg/pulsar.svg)](https://charts.stackradar.io/charts/cnieg/pulsar)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.