StackRadar

pulsar Helm chart

cnieg

Scored 14 Sept 2026

Apache Pulsar Helm chart for Kubernetes

Latest 1.0.8 4 years agodeploys tag v0.1.0 0Artifact Hub

pulsar 1.0.8 deploys 2 container images: apachepulsar/pulsar-manager and apachepulsar/pulsar. Across them, 749 findings30 critical, 59 high 15 on CISA KEV. The highest contribution is GHSA-jfh8-c2jp-5v3q in log4j-core 2.10.0, fixed in 2.12.2.

Radar Score

16,8603059324336

749 findings over 2 of 2 images measured

KEV ×15 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
apachepulsar/pulsar-managerv0.1.0214618314310,210
apachepulsar/pulsar×172.6.19131411936,650

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

266 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumGHSA-g5h3-w546-pj7fspring-boot-actuator-autoconfigure@2.0.2.RELEASE2.5.15
MediumGHSA-mvr2-9pj6-7w5jguava@11.0.224.1.1-android
MediumGHSA-qxf4-chvg-4r8rtomcat-embed-core@8.5.318.5.51
MediumALPINE-CVE-2020-24977libxml2@2.9.9-r22.9.9-r3
MediumGHSA-v7wg-cpwc-24m4postgresql@42.2.542.2.25
MediumPYSEC-2025-49setuptools@40.6.3.post2019011678.1.1
MediumGHSA-wgmr-mf83-7x4jhttp2-server@9.4.11.v201806059.4.47
MediumGHSA-f256-j965-7f32netty-codec-http2@4.1.24.Final4.1.61.Final
MediumGHSA-f256-j965-7f32netty@3.10.6.Finalno fix listed
MediumGHSA-c35h-w8hj-mm55pulsar-proxy@2.6.12.10.6
MediumGHSA-qq48-m4jx-xqh8mybatis@3.4.63.5.6
MediumALPINE-CVE-2020-25692openldap@2.4.48-r12.4.48-r2
MediumALPINE-CVE-2019-1549openssl@1.1.1b-r11.1.1d-r0
MediumGHSA-86wm-rrjm-8wh8jetty-server@9.4.10.v201805039.4.35.v20201120
MediumGHSA-xc67-hjx6-cgg6jetty-server@9.4.10.v201805039.4.17.v20190418
MediumGHSA-wc4r-xq3c-5cf3tomcat-embed-core@8.5.31no fix listed
MediumGHSA-hrmr-f5m6-m9pqcommons-compress@1.8.11.18
MediumGHSA-r6j3-px5g-cq3xtomcat-embed-core@8.5.318.5.94
MediumGHSA-wr62-c79q-cv37tomcat-embed-core@8.5.31no fix listed
MediumGHSA-5m62-pw8w-7w9ftomcat-embed-core@8.5.319.0.118
MediumALPINE-CVE-2018-14498libjpeg-turbo@1.5.3-r41.5.3-r5
MediumALPINE-CVE-2020-25694postgresql@11.7-r011.10-r0
MediumGHSA-rvgg-f8qm-6h7jvertx-web@3.4.13.5.3
MediumGHSA-25xr-qj8w-c4vftomcat-embed-core@8.5.31no fix listed
MediumGHSA-hh26-6xwr-ggv7spring-beans@5.0.6.RELEASE5.2.22.RELEASE
MediumGHSA-4j3c-42xv-3f84tomcat-embed-core@8.5.31no fix listed
MediumGHSA-vp98-w2p3-mv35log4j@1.2.172.0
MediumALPINE-CVE-2020-14349postgresql@11.7-r011.9-r0
MediumGHSA-rhrv-645h-fjfhavro@1.8.21.11.3
MediumGHSA-r38f-c4h4-hqq2postgresql@42.2.542.2.26
MediumDLA-3559-1libssh2@1.8.0-2.11.8.0-2.1+deb10u1
MediumDLA-3477-1python3.7@3.7.3-2+deb10u23.7.3-2+deb10u5
MediumGHSA-w9fj-cfpg-grvvnetty-codec-http2@4.1.24.Final4.1.132.Final
MediumGHSA-wx5j-54mm-rqqqnetty-codec-http@4.1.24.Final4.1.71.Final
MediumGHSA-wx5j-54mm-rqqqnetty@3.10.6.Finalno fix listed
MediumGHSA-h2fw-rfh5-95r3tomcat-embed-core@8.5.31no fix listed
MediumGHSA-45xm-v8gq-7jqxvertx-core@3.4.13.5.4
MediumGHSA-9xv2-5v5q-p794tomcat-embed-core@8.5.31no fix listed
MediumGHSA-wrvw-hg22-4m67protobuf-java@2.4.13.16.1
MediumGHSA-9w3m-gqgf-c4p9snakeyaml@1.191.32
MediumDSA-4920-1libx11@2:1.6.7-12:1.6.7-1+deb10u2
MediumDSA-4994-1bind9@1:9.11.5.P4+dfsg-5.1+deb10u11:9.11.5.P4+dfsg-5.1+deb10u6
MediumGHSA-6mjq-h674-j845netty-handler@4.1.24.Final4.1.94.Final
MediumGHSA-j8r2-6x86-q33qrequests@2.24.02.31.0
MediumGHSA-f26x-pr96-vw86spring-core@5.0.6.RELEASE5.0.7.RELEASE
MediumDSA-4944-1krb5@1.17-31.17-3+deb10u2
MediumGHSA-p22x-g9px-3945tomcat-embed-core@8.5.318.5.83
MediumGHSA-pvp8-3xj6-8c6xcommons-configuration@1.10no fix listed
MediumPYSEC-2023-192urllib3@1.25.102.0.6
MediumGHSA-9rgv-h7x4-qw8gjetty-server@9.4.10.v201805039.4.11.v20180605

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.8latest4 years agov0.1.0305932433616,860

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cnieg/pulsar.svg)](https://charts.stackradar.io/charts/cnieg/pulsar)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.