StackRadar

drogue-cloud-core 0.7.11 Helm chart

drogue-iotVerified publisher

Scored 14 Sept 2026

Drogue IoT Cloud core installation

Version 0.7.11 3 years agoapp version 0.11.0 0Artifact Hub

drogue-cloud-core 0.7.11 deploys 22 container images: bitnami/postgresql, ghcr.io/drogue-iot/mqtt-integration, ghcr.io/drogue-iot/websocket-integration, swaggerapi/swagger-ui and 18 more. Across the 21 measured, 2,823 findings141 critical, 193 high 63 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.80.0-r1, fixed in 8.4.0-r0. Chart.yaml declares kubeVersion >= 1.22.0-0; rendered for Kubernetes 1.22.0.

Radar Score

55,6661411938501,639

2,823 findings over 21 of 22 images measured

KEV ×63 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

22 images
ImageTagVulnerabilitiesRadar Score
bitnami/postgresql15unmeasured
ghcr.io/drogue-iot/mqtt-integration×30.11.07937692,505
ghcr.io/drogue-iot/websocket-integration0.11.07937692,505
swaggerapi/swagger-uiv4.12.031143101,879
ghcr.io/drogue-iot/console-backend0.11.07937692,505
ghcr.io/drogue-iot/console-frontend0.11.091251903,318
ghcr.io/drogue-iot/authentication-service0.11.07937692,505
ghcr.io/drogue-iot/device-management-controller0.11.07937692,505
ghcr.io/drogue-iot/knative-operator0.11.07937692,505
ghcr.io/drogue-iot/outbox-controller0.11.07937692,505
ghcr.io/drogue-iot/device-management-service0.11.07937692,505
ghcr.io/drogue-iot/topic-strimzi-operator0.11.07937692,505
ghcr.io/drogue-iot/ttn-operator0.11.07937692,505
ghcr.io/drogue-iot/user-auth-service0.11.07937692,505
ghcr.io/drogue-iot/device-state-service0.11.07937692,505
ghcr.io/drogue-iot/coap-endpoint0.11.07937692,505
ghcr.io/drogue-iot/command-endpoint0.11.07937692,505
ghcr.io/drogue-iot/http-endpoint0.11.07937692,505
ghcr.io/drogue-iot/mqtt-endpoint×30.11.07937692,505
ghcr.io/drogue-iot/test-cert-generator0.11.04733632,044
ghcr.io/drogue-iot/database-migration0.11.08937722,615
quay.io/keycloak/keycloak20.0510943005,730

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

176 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumRHSA-2026:28212nginx@1:1.20.1-13.el91:1.24.0-7.module+el9.8.0+24379+0344c460.2
MediumRHSA-2023:2570krb5@1.19.1-23.el9_10:1.20.1-8.el9
MediumRHSA-2025:11035lz4@1.8.3-3.el8_40:1.8.3-5.el8_10
MediumGHSA-24rp-q3w6-vc56postgresql@42.5.142.5.5
MediumRHSA-2023:7151python3@3.6.8-48.el8_70:3.6.8-56.el8_9
MediumRHSA-2023:7176python-pip@9.0.3-22.el80:9.0.3-23.el8
MediumRHSA-2024:0889oniguruma@6.8.2-2.el80:6.8.2-2.1.el8_9
MediumRHSA-2023:0339sqlite@3.34.1-5.el90:3.34.1-6.el9_1
MediumRHSA-2022:8637krb5@1.19.1-23.el9_10:1.19.1-24.el9_1
MediumALPINE-CVE-2022-32221curl@7.80.0-r17.80.0-r4
MediumRHSA-2026:36331nginx@1:1.20.1-13.el92:1.20.1-28.el9_8.4
MediumGHSA-fhw8-8j55-vwgqsshd-common@2.7.02.9.2
MediumALPINE-CVE-2022-4304openssl@1.1.1n-r01.1.1t-r0
MediumALPINE-CVE-2022-40304libxml2@2.9.14-r02.9.14-r2
MediumRHSA-2023:0833python3@3.6.8-48.el8_70:3.6.8-48.el8_7.1
MediumRHSA-2026:25239openssl@1:3.0.1-43.el9_01:3.5.5-4.el9_8
MediumALPINE-CVE-2022-1586pcre2@10.39-r010.40-r0
MediumALPINE-CVE-2022-32205curl@7.80.0-r17.80.0-r2
MediumALPINE-CVE-2022-1587pcre2@10.39-r010.40-r0
MediumRHSA-2023:6699krb5@1.19.1-23.el9_10:1.21.1-1.el9
MediumALPINE-CVE-2023-0215openssl@1.1.1n-r01.1.1t-r0
MediumRHSA-2026:26275openssl@1:1.1.1k-7.el8_61:1.1.1k-16.el8_6
MediumRHSA-2024:2447openssl@1:3.0.1-43.el9_01:3.0.7-27.el9
MediumALPINE-CVE-2022-42915curl@7.80.0-r17.80.0-r4
MediumALPINE-CVE-2023-0464openssl@1.1.1n-r01.1.1t-r2
MediumRHSA-2026:66542nginx@1:1.20.1-13.el92:1.20.1-28.el9_8.6
MediumGHSA-2cww-fgmg-4jqckeycloak-services@20.0.524.0.5
MediumALPINE-CVE-2023-32002nodejs@16.14.2-r016.20.2-r0
MediumALPINE-CVE-2023-27534curl@7.80.0-r18.0.1-r0
MediumALPINE-CVE-2022-32208curl@7.80.0-r17.80.0-r2
MediumALPINE-CVE-2022-35255nodejs@16.14.2-r016.17.1-r0
MediumRHSA-2024:0310openssl@1:3.0.1-43.el9_01:3.0.7-25.el9_3
MediumALPINE-CVE-2022-27406freetype@2.11.1-r12.11.1-r2
MediumGHSA-98qh-xjc8-98pqpostgresql@42.5.142.7.11
MediumALPINE-CVE-2023-27533curl@7.80.0-r18.0.1-r0
MediumRHSA-2023:7877openssl@1:1.1.1k-7.el8_61:1.1.1k-12.el8_9
MediumGHSA-cx63-2mw6-8hw5setuptools@39.2.070.0.0
MediumRHSA-2024:5530python-setuptools@39.2.0-6.el80:39.2.0-8.el8_10
MediumRHSA-2023:2523openssl@1:3.0.1-43.el9_01:3.0.7-6.el9_2
MediumGHSA-gpvv-69j7-gwj8pip@9.0.319.2
MediumALPINE-CVE-2022-27782curl@7.80.0-r17.80.0-r2
MediumALPINE-CVE-2022-27405freetype@2.11.1-r12.11.1-r2
MediumGHSA-jjjh-jjxp-wpffjackson-databind@2.13.32.13.4.2
MediumGHSA-rgv9-q543-rqg4jackson-databind@2.13.32.13.4
MediumALPINE-CVE-2022-27781curl@7.80.0-r17.80.0-r2
MediumRHSA-2024:7848openssl@1:1.1.1k-7.el8_61:1.1.1k-14.el8_6
MediumRHSA-2025:10698libxml2@2.9.7-15.el80:2.9.7-21.el8_10.1
MediumRHSA-2025:10699libxml2@2.9.13-2.el90:2.9.13-10.el9_6
MediumALPINE-CVE-2022-2309libxml2@2.9.14-r02.9.14-r1
MediumGHSA-r9hx-vwmv-q579setuptools@39.2.065.5.1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.7.11latest3 years ago0.11.01411938501,63955,666

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/drogue-iot/drogue-cloud-core.svg)](https://charts.stackradar.io/charts/drogue-iot/drogue-cloud-core)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.