StackRadar

directus Helm chart

directus-io

Scored 14 Sept 2026

A Helm chart for installing Directus on Kubernetes. Directus is a real-time API and App dashboard for managing SQL database content.

Latest 2.1.0 1 month agoapp version 12.0.2 1Artifact Hub

directus 2.1.0 deploys 3 container images: directus/directus, bitnamilegacy/mysql and bitnamilegacy/redis. Across them, 744 findings1 critical, 2 high. The highest contribution is BIT-redis-2025-49844 in redis 8.2.1-0, fixed in 6.2.20.

Radar Score

7,4731289651

744 findings over 3 of 3 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
directus/directus12.0.200122132,091
bitnamilegacy/mysql×29.4.0-debian-12-r101362522,874
bitnamilegacy/redis×28.2.1-debian-12-r011411862,508

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

480 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-3184util-linux@2.38.1-5+deb12u3no fix listed
LowGHSA-58qx-3vcg-4xpxws@8.18.38.20.1
LowGHSA-4vpr-x523-8j87svgo@4.0.14.1.0
LowGHSA-jr45-8vmc-qm54undici@7.24.57.29.0
LowDEBIAN-CVE-2026-7010perl@5.36.0-7+deb12u2no fix listed
LowDEBIAN-CVE-2026-19487perl@5.36.0-7+deb12u2no fix listed
LowGHSA-26pp-8wgv-hjvmhono@4.12.44.12.12
LowGHSA-3v7f-55p6-f55ppicomatch@4.0.34.0.4
LowDEBIAN-CVE-2026-89158pcre2@10.42-110.42-1+deb12u1
LowGHSA-9vqf-7f2p-gf9vhono@4.12.44.12.16
LowDEBIAN-CVE-2025-27587openssl@3.0.17-1~deb12u1no fix listed
LowGHSA-f38q-mgvj-vph7protobufjs@7.5.67.6.3
LowALPINE-CVE-2026-42769openssl@3.5.6-r03.5.7-r0
LowGHSA-7q8q-rj6j-mhjqaxios@1.16.11.18.0
LowDEBIAN-CVE-2013-4392systemd@252.38-1~deb12u1no fix listed
LowGHSA-g6gw-c38x-mqfchono@4.12.44.13.5
LowGHSA-h67p-54hq-rp68js-yaml@4.1.14.2.0
LowGHSA-92pp-h63x-v22m@hono/node-server@1.19.101.19.13
LowDEBIAN-CVE-2026-78408util-linux@2.38.1-5+deb12u3no fix listed
LowGHSA-3f6p-5ww8-9rcrmysql2@3.15.33.22.0
LowDEBIAN-CVE-2026-41989libgcrypt20@1.10.1-31.10.1-3+deb12u1
LowGHSA-j3f2-48v5-ccwwprotobufjs@7.5.67.6.5
LowGHSA-3jxr-9vmj-r5cpbrace-expansion@2.0.32.1.2
LowGHSA-p88m-4jfj-68fvundici@7.24.57.28.0
LowGO-2026-4981stdlib@go1.23.121.25.10
LowDEBIAN-CVE-2023-31439systemd@252.38-1~deb12u1no fix listed
LowGHSA-vmf3-w455-68vhtar@7.5.117.5.16
LowGHSA-8988-4f7v-96qf@opentelemetry/core@2.1.02.8.0
LowGO-2026-4977stdlib@go1.23.121.25.10
LowGHSA-xpcf-pg52-r92ghono@4.12.44.12.12
LowGHSA-x5gf-qvw8-r2rmpm2@6.0.147.0.0
LowDEBIAN-CVE-2023-31437systemd@252.38-1~deb12u1no fix listed
LowDEBIAN-CVE-2025-68973gnupg2@2.2.40-1.12.2.40-1.1+deb12u2
LowGO-2026-4986stdlib@go1.23.121.25.10
LowGO-2026-4918stdlib@go1.23.121.25.10
LowGO-2026-4337stdlib@go1.23.121.24.13
LowDEBIAN-CVE-2026-4438glibc@2.36-9+deb12u102.36-9+deb12u14
LowDEBIAN-CVE-2023-31438systemd@252.38-1~deb12u1no fix listed
LowDEBIAN-CVE-2025-3198binutils@2.40-2no fix listed
LowGO-2026-4601stdlib@go1.23.121.25.8
LowGHSA-j6c9-x7qj-28xfhono@4.12.44.12.25
LowDEBIAN-CVE-2026-78410util-linux@2.38.1-5+deb12u3no fix listed
LowGHSA-866g-f22w-33x8@ai-sdk/provider-utils@4.0.194.0.33
LowDEBIAN-CVE-2026-89161pcre2@10.42-110.42-1+deb12u1
LowGO-2026-5026stdlib@go1.23.121.25.13
LowDEBIAN-CVE-2025-14104util-linux@2.38.1-5+deb12u3no fix listed
LowGHSA-54fx-42gc-7vw4hono@4.12.44.12.34
LowDEBIAN-CVE-2026-42014gnutls28@3.7.9-2+deb12u53.7.9-2+deb12u7
LowGO-2026-4342stdlib@go1.23.121.24.12
LowDEBIAN-CVE-2026-4105systemd@252.38-1~deb12u1252.39-1~deb12u2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.1.0latest1 month ago12.0.212896517,473

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/directus-io/directus.svg)](https://charts.stackradar.io/charts/directus-io/directus)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.