StackRadar

loki-stack Helm chart

common-chartsVerified publisher

Scored 14 Sept 2026

Observability stack - Loki for logs, Grafana for visualization, Prometheus for metrics, and Grafana Alloy for log collection (alternative to deprecated Promtail) [DOCS => https://rishang.github.io/helm-charts/loki-stack/introduction]

Latest 1.0.3 24 days agodeploys tag v1.18.0 0Artifact Hub

loki-stack 1.0.3 deploys 12 container images: grafana/alloy, quay.io/prometheus-operator/prometheus-config-reloader, quay.io/prometheus/node-exporter, quay.io/kiwigrid/k8s-sidecar and 8 more. Across them, 556 findings0 critical, 2 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.5.4-r0, fixed in 3.5.5-r0.

Radar Score

5,3290273481

556 findings over 12 of 12 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

12 images
ImageTagVulnerabilitiesRadar Score
grafana/alloyv1.18.0009106989
quay.io/prometheus-operator/prometheus-config-reloaderv0.91.000542418
quay.io/prometheus/node-exporterv1.12.1-distroless0001278
quay.io/kiwigrid/k8s-sidecar×22.10.000412199
grafana/grafana13.1.100857628
registry.k8s.io/kube-state-metrics/kube-state-metricsv2.19.100024163
quay.io/prometheus-operator/prometheus-operatorv0.92.100021144
library/memcached1.6.39-alpine011730674
prom/memcached-exporterv0.15.400562561
grafana/loki3.6.1100656541
kiwigrid/k8s-sidecar2.5.0011951878
ghcr.io/jkroepke/kube-webhook-certgen×21.8.5000856

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

264 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGO-2026-5841github.com/klauspost/compress@v1.18.51.18.7
LowGO-2026-5932golang.org/x/crypto@v0.49.0no fix listed
LowGO-2026-6061google.golang.org/grpc@v1.80.01.82.1
LowGO-2026-6094github.com/google/cel-go@v0.28.10.30.0
LowUSN-8625-1openssl@3.0.13-0ubuntu3.113.0.13-0ubuntu3.12
LowUSN-8688-1pam@1.5.3-5ubuntu5.51.5.3-5ubuntu5.7
LowALPINE-CVE-2025-46394busybox@1.37.0-r191.37.0-r20
LowUBUNTU-CVE-2026-27171zlib@1:1.3.dfsg-3.1ubuntu2.11:1.3.dfsg-3.1ubuntu2.2
LowUBUNTU-CVE-2026-40228systemd@255.4-1ubuntu8.16no fix listed
LowUBUNTU-CVE-2026-57062gnupg2@2.4.4-2ubuntu17.42.4.4-2ubuntu17.6
LowGHSA-6vgw-5pg2-w6jppip@25.326.0
LowUBUNTU-CVE-2026-53910diffutils@1:3.10-1build11:3.10-1ubuntu0.1
LowALPINE-CVE-2024-58251busybox@1.37.0-r191.37.0-r20
LowUBUNTU-CVE-2026-6368glibc@2.39-0ubuntu8.72.39-0ubuntu8.9

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.3latest24 days agov1.18.002734815,329

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/common-charts/loki-stack.svg)](https://charts.stackradar.io/charts/common-charts/loki-stack)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.