StackRadar

drogue-cloud-core 0.7.11 Helm chart

drogue-iotVerified publisher

Scored 14 Sept 2026

Drogue IoT Cloud core installation

Version 0.7.11 3 years agoapp version 0.11.0 0Artifact Hub

drogue-cloud-core 0.7.11 deploys 22 container images: bitnami/postgresql, ghcr.io/drogue-iot/mqtt-integration, ghcr.io/drogue-iot/websocket-integration, swaggerapi/swagger-ui and 18 more. Across the 21 measured, 2,823 findings141 critical, 193 high 63 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.80.0-r1, fixed in 8.4.0-r0. Chart.yaml declares kubeVersion >= 1.22.0-0; rendered for Kubernetes 1.22.0.

Radar Score

55,6661411938501,639

2,823 findings over 21 of 22 images measured

KEV ×63 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

22 images
ImageTagVulnerabilitiesRadar Score
bitnami/postgresql15unmeasured
ghcr.io/drogue-iot/mqtt-integration×30.11.07937692,505
ghcr.io/drogue-iot/websocket-integration0.11.07937692,505
swaggerapi/swagger-uiv4.12.031143101,879
ghcr.io/drogue-iot/console-backend0.11.07937692,505
ghcr.io/drogue-iot/console-frontend0.11.091251903,318
ghcr.io/drogue-iot/authentication-service0.11.07937692,505
ghcr.io/drogue-iot/device-management-controller0.11.07937692,505
ghcr.io/drogue-iot/knative-operator0.11.07937692,505
ghcr.io/drogue-iot/outbox-controller0.11.07937692,505
ghcr.io/drogue-iot/device-management-service0.11.07937692,505
ghcr.io/drogue-iot/topic-strimzi-operator0.11.07937692,505
ghcr.io/drogue-iot/ttn-operator0.11.07937692,505
ghcr.io/drogue-iot/user-auth-service0.11.07937692,505
ghcr.io/drogue-iot/device-state-service0.11.07937692,505
ghcr.io/drogue-iot/coap-endpoint0.11.07937692,505
ghcr.io/drogue-iot/command-endpoint0.11.07937692,505
ghcr.io/drogue-iot/http-endpoint0.11.07937692,505
ghcr.io/drogue-iot/mqtt-endpoint×30.11.07937692,505
ghcr.io/drogue-iot/test-cert-generator0.11.04733632,044
ghcr.io/drogue-iot/database-migration0.11.08937722,615
quay.io/keycloak/keycloak20.0510943005,730

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

High findings

30 distinct across the version’s images

High: findings whose contribution to the Radar Score is 40–69. Show every band

SeverityAdvisoryPackageFixed in
HighRHSA-2025:0083cups@1:2.2.6-50.el81:2.2.6-62.el8_10
HighRHSA-2023:0946openssl@1:3.0.1-43.el9_01:3.0.1-47.el9_1
HighRHSA-2023:1405openssl@1:1.1.1k-7.el8_61:1.1.1k-9.el8_7
HighALPINE-CVE-2023-0286openssl@1.1.1n-r01.1.1t-r0
HighRHSA-2025:1346KEVgcc@11.3.1-2.1.el90:11.5.0-5.el9_5
HighALPINE-CVE-2022-32214nodejs@16.14.2-r016.17.1-r0
HighALPINE-CVE-2023-2650openssl@1.1.1n-r01.1.1u-r0
HighRHSA-2023:3722openssl@1:3.0.1-43.el9_01:3.0.7-16.el9_2
HighRHSA-2025:9318javapackages-tools@5.3.0-1.module+el8+2447+6f56d9a60:5.3.0-2.module+el8.10.0+23274+27840b45
HighRHSA-2024:0628libssh@0.9.6-3.el80:0.9.6-13.el8_9
HighALPINE-CVE-2022-32215nodejs@16.14.2-r016.17.1-r0
HighALPINE-CVE-2022-37434zlib@1.2.12-r01.2.12-r2
HighRHSA-2024:5529curl@7.76.1-19.el90:7.76.1-29.el9_4.1
HighRHSA-2026:6923nginx@1:1.20.1-13.el91:1.24.0-5.module+el9.7.0+24151+c43a3acf.2
HighRHSA-2026:7002nginx@1:1.20.1-13.el92:1.20.1-24.el9_7.2
HighRHSA-2026:7343nginx@1:1.20.1-13.el92:1.26.3-2.module+el9.7.0+24173+4204b761.1
HighRHSA-2024:6783openssl@1:3.0.1-43.el9_01:3.0.7-28.el9_4
HighRHSA-2024:3501nghttp2@1.43.0-5.el90:1.43.0-5.el9_4.3
HighALPINE-CVE-2022-32213nodejs@16.14.2-r016.17.1-r0
HighRHSA-2024:9333openssl@1:3.0.1-43.el9_01:3.2.2-6.el9_5
HighRHSA-2024:9474krb5@1.19.1-23.el9_10:1.21.1-4.el9_5
HighRHSA-2023:0173libxml2@2.9.7-15.el80:2.9.7-15.el8_7.1
HighRHSA-2023:0338libxml2@2.9.13-2.el90:2.9.13-3.el9_1
HighALPINE-CVE-2022-40303libxml2@2.9.14-r02.9.14-r2
HighALPINE-CVE-2022-32206curl@7.80.0-r17.80.0-r2
HighRHSA-2023:3591python3@3.6.8-48.el8_70:3.6.8-51.el8_8.1
HighALPINE-CVE-2022-4450openssl@1.1.1n-r01.1.1t-r0
HighRHSA-2025:21776expat@2.2.5-10.el8_7.10:2.5.0-1.el8_10
HighALPINE-CVE-2022-43551curl@7.80.0-r17.80.0-r5
HighALPINE-CVE-2022-32207curl@7.80.0-r17.80.0-r2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.7.11latest3 years ago0.11.01411938501,63955,666

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/drogue-iot/drogue-cloud-core.svg)](https://charts.stackradar.io/charts/drogue-iot/drogue-cloud-core)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.