StackRadar

pulsar Helm chart

cnieg

Scored 14 Sept 2026

Apache Pulsar Helm chart for Kubernetes

Latest 1.0.8 4 years agodeploys tag v0.1.0 0Artifact Hub

pulsar 1.0.8 deploys 2 container images: apachepulsar/pulsar-manager and apachepulsar/pulsar. Across them, 749 findings30 critical, 59 high 15 on CISA KEV. The highest contribution is GHSA-jfh8-c2jp-5v3q in log4j-core 2.10.0, fixed in 2.12.2.

Radar Score

16,8603059324336

749 findings over 2 of 2 images measured

KEV ×15 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
apachepulsar/pulsar-managerv0.1.0214618314310,210
apachepulsar/pulsar×172.6.19131411936,650

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

266 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumGHSA-w7f5-jrpr-5c2mavatica-core@1.13.01.22.0
MediumGHSA-27xj-rqx5-2255jackson-databind@2.9.52.9.10.4
MediumGHSA-wm9w-rjj3-j356tomcat-embed-core@8.5.31no fix listed
MediumGHSA-vjw7-6gfq-6wf5vertx-web@3.4.13.9.4
MediumGHSA-88cc-g835-76rppostgresql@42.2.542.2.13
MediumALPINE-CVE-2020-28196krb5@1.15.5-r01.15.5-r1
MediumALPINE-CVE-2020-11655sqlite@3.26.0-r33.28.0-r3
MediumGHSA-mwcx-532g-8pq3jetty-server@9.4.10.v201805039.4.11.v20180605
MediumGHSA-rpr3-cw39-3pxhjackson-databind@2.9.52.9.10.4
MediumGHSA-qmqc-x3r4-6v39jackson-databind@2.9.52.9.10
MediumGHSA-pq64-v7f5-gqh8pygments@2.3.12.7.4
MediumGHSA-w559-623p-vfg8pagehelper@5.1.35.3.1
MediumGHSA-wgh7-54f2-x98rhttp2-hpack@9.4.11.v201806059.4.53
MediumGHSA-cghx-9gcr-r42xclient-java@2.0.09.0.2
MediumALPINE-CVE-2021-23841openssl@1.1.1b-r11.1.1j-r0
MediumDLA-3432-1python2.7@2.7.16-2+deb10u12.7.16-2+deb10u2
MediumGHSA-r29c-68gh-xp6xtomcat-embed-core@8.5.319.0.118
MediumDLA-3172-1libxml2@2.9.4+dfsg1-7+b32.9.4+dfsg1-7+deb10u5
MediumGHSA-mmxm-8w33-wc4hhttp2-common@9.4.11.v201806059.4.58
MediumALPINE-CVE-2020-1971openssl@1.1.1b-r11.1.1i-r0
MediumALPINE-CVE-2019-19244sqlite@3.26.0-r33.28.0-r2
MediumGHSA-q2q7-5pp4-w6pgurllib3@1.25.101.26.5
MediumGHSA-98qh-xjc8-98pqpostgresql@42.2.542.7.11
MediumGHSA-q3mw-pvr8-9ggctomcat-embed-core@8.5.318.5.93
MediumGHSA-hgjh-9rj2-g67jspring-web@5.0.6.RELEASE5.3.33
MediumGHSA-7r82-7xv7-xcpjhttpclient@4.5.54.5.13
MediumGHSA-ff77-26x5-69crtomcat-embed-core@8.5.31no fix listed
MediumGHSA-cx63-2mw6-8hw5setuptools@40.6.3.post2019011670.0.0
MediumGHSA-h4x4-5qp2-wp46jackson-datatype-jsr310@2.9.52.9.8
MediumGHSA-c2x9-vw5h-39vcpulsar-functions-worker@2.4.12.10.6
MediumGHSA-7286-pgfv-vxvhzookeeper@3.5.53.7.2
MediumGHSA-668q-qrv7-99fmlogback-core@1.2.31.2.9
MediumGHSA-38jv-5279-wg99urllib3@1.25.102.6.3
MediumALPINE-CVE-2020-25709openldap@2.4.48-r12.4.48-r2
MediumGHSA-jjjh-jjxp-wpffjackson-databind@2.9.52.12.7.1
MediumGHSA-rgv9-q543-rqg4jackson-databind@2.9.52.12.7.1
MediumGHSA-735f-pc8j-v9w8protobuf-java@2.4.13.25.5
MediumALPINE-CVE-2019-16168sqlite@3.26.0-r33.28.0-r1
MediumALPINE-CVE-2019-2201libjpeg-turbo@1.5.3-r41.5.3-r6
MediumGHSA-9w8r-397f-prfhpygments@2.3.12.7.4
MediumGHSA-h6fc-48rj-7qqhtomcat-embed-core@8.5.319.0.118
MediumGHSA-3mc7-4q67-w48msnakeyaml@1.191.31
MediumDLA-3103-1zlib@1:1.2.11.dfsg-11:1.2.11.dfsg-1+deb10u2
MediumALPINE-CVE-2020-25696postgresql@11.7-r011.10-r0
MediumGHSA-gwrp-pvrq-jmwvcommons-io@2.52.7
MediumALPINE-CVE-2020-25710openldap@2.4.48-r12.4.48-r2
MediumGHSA-qwmp-2cf2-g9g6wheel@0.35.10.38.1
MediumDSA-4697-1gnutls28@3.6.7-4+deb10u33.6.7-4+deb10u4
MediumGHSA-fccv-jmmp-qg76tomcat-embed-core@8.5.318.5.96
MediumGHSA-r9hx-vwmv-q579setuptools@40.6.3.post2019011665.5.1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.8latest4 years agov0.1.0305932433616,860

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cnieg/pulsar.svg)](https://charts.stackradar.io/charts/cnieg/pulsar)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.