StackRadar

romm Helm chart

crystalnetVerified publisher

Scored 14 Sept 2026

RomM (Rom Manager) is a web based retro roms manager integrated with IGDB.

Latest 0.2.20 2 years agoapp version 2.3.1 1Artifact Hub

romm 0.2.20 deploys 3 container images: zurdi15/romm, bitnami/mariadb and bitnami/redis. Across the 1 measured, 134 findings0 critical, 5 high 1 on CISA KEV. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.0.12-r1, fixed in 3.0.19-r0. Chart.yaml declares kubeVersion >=1.22.0-0; rendered for Kubernetes 1.22.0.

Radar Score

1,944054385

134 findings over 1 of 3 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
zurdi15/romm2.3.10543851,944
bitnami/mariadb11.2.2-debian-11-r3unmeasured
bitnami/redis7.2.4-debian-11-r2unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

85 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2023-42364busybox@1.35.0-r291.35.0-r31
LowALPINE-CVE-2023-42363busybox@1.35.0-r291.35.0-r31
LowGHSA-9f5j-8jwj-x28gecdsa@0.18.00.19.2
LowALPINE-CVE-2023-42366busybox@1.35.0-r291.35.0-r30
LowALPINE-CVE-2023-42365busybox@1.35.0-r291.35.0-r31
LowGHSA-pq67-6m6q-mj2vurllib3@2.0.72.5.0
LowALPINE-CVE-2024-6874curl@8.5.0-r08.9.0-r0
LowALPINE-CVE-2023-52426expat@2.5.0-r02.6.0-r0
LowGHSA-65pc-fj4g-8rjxidna@3.43.15
LowGHSA-9wx4-h78v-vm56requests@2.31.02.32.0
LowGHSA-mj87-hwqh-73pjpython-multipart@0.0.60.0.26
LowGHSA-qccp-gfcp-xxvcurllib3@2.0.72.7.0
LowALPINE-CVE-2024-13176openssl@3.0.12-r13.0.19-r0
LowGHSA-537c-gmf6-5ccfcryptography@41.0.648.0.1
LowGHSA-x746-7m8f-x49cstarlette@0.27.01.1.0
LowPYSEC-2026-2275requests@2.31.02.33.0
LowPYSEC-2025-185python-jose@3.3.0no fix listed
LowPYSEC-2026-248starlette@0.27.01.3.0
LowALPINE-CVE-2026-22795openssl@3.0.12-r13.0.19-r0
LowGHSA-m959-cc7f-wv43cryptography@41.0.646.0.6
LowGHSA-r73j-pqj5-w3x7pillow@10.1.012.2.0
LowGHSA-jp4c-xjxw-mgf9pip@23.3.226.1
LowPYSEC-2024-232python-jose@3.3.03.4.0
LowGHSA-wjx4-4jcj-g98jpillow@10.1.012.2.0
LowGHSA-v9pg-7xvm-68hfpython-multipart@0.0.60.0.31
LowGHSA-h4gh-qq45-vh27cryptography@41.0.643.0.1
LowALPINE-CVE-2025-68160openssl@3.0.12-r13.0.19-r0
LowGHSA-4x4j-2g7c-83w6pillow@10.1.012.3.0
LowGHSA-vffw-93wf-4j4qpython-multipart@0.0.60.0.30
LowGHSA-58qw-9mgm-455vpip@23.3.226.1
LowGHSA-6jv3-5f52-599mpython-multipart@0.0.60.0.30
LowALPINE-CVE-2025-69418openssl@3.0.12-r13.0.19-r0
LowALPINE-CVE-2015-2104python3@3.10.13-r03.10.15-r0
LowGHSA-5239-wwwm-4pmqpygments@2.16.12.20.0
LowGHSA-6vgw-5pg2-w6jppip@23.3.226.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.2.20latest2 years ago2.3.10543851,944

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/crystalnet/romm.svg)](https://charts.stackradar.io/charts/crystalnet/romm)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 10 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.