StackRadar

drogue-cloud-core 0.7.11 Helm chart

drogue-iotVerified publisher

Scored 14 Sept 2026

Drogue IoT Cloud core installation

Version 0.7.11 3 years agoapp version 0.11.0 0Artifact Hub

drogue-cloud-core 0.7.11 deploys 22 container images: bitnami/postgresql, ghcr.io/drogue-iot/mqtt-integration, ghcr.io/drogue-iot/websocket-integration, swaggerapi/swagger-ui and 18 more. Across the 21 measured, 2,823 findings141 critical, 193 high 63 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.80.0-r1, fixed in 8.4.0-r0. Chart.yaml declares kubeVersion >= 1.22.0-0; rendered for Kubernetes 1.22.0.

Radar Score

55,6661411938501,639

2,823 findings over 21 of 22 images measured

KEV ×63 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

22 images
ImageTagVulnerabilitiesRadar Score
bitnami/postgresql15unmeasured
ghcr.io/drogue-iot/mqtt-integration×30.11.07937692,505
ghcr.io/drogue-iot/websocket-integration0.11.07937692,505
swaggerapi/swagger-uiv4.12.031143101,879
ghcr.io/drogue-iot/console-backend0.11.07937692,505
ghcr.io/drogue-iot/console-frontend0.11.091251903,318
ghcr.io/drogue-iot/authentication-service0.11.07937692,505
ghcr.io/drogue-iot/device-management-controller0.11.07937692,505
ghcr.io/drogue-iot/knative-operator0.11.07937692,505
ghcr.io/drogue-iot/outbox-controller0.11.07937692,505
ghcr.io/drogue-iot/device-management-service0.11.07937692,505
ghcr.io/drogue-iot/topic-strimzi-operator0.11.07937692,505
ghcr.io/drogue-iot/ttn-operator0.11.07937692,505
ghcr.io/drogue-iot/user-auth-service0.11.07937692,505
ghcr.io/drogue-iot/device-state-service0.11.07937692,505
ghcr.io/drogue-iot/coap-endpoint0.11.07937692,505
ghcr.io/drogue-iot/command-endpoint0.11.07937692,505
ghcr.io/drogue-iot/http-endpoint0.11.07937692,505
ghcr.io/drogue-iot/mqtt-endpoint×30.11.07937692,505
ghcr.io/drogue-iot/test-cert-generator0.11.04733632,044
ghcr.io/drogue-iot/database-migration0.11.08937722,615
quay.io/keycloak/keycloak20.0510943005,730

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

593 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumGHSA-q6cq-mhr2-jmr5netty-codec-haproxy@4.1.86.Final4.1.136.Final
MediumALPINE-CVE-2023-1999libwebp@1.2.2-r01.2.2-r1
MediumRHBA-2024:2413glibc@2.34-40.el90:2.34-100.el9
MediumRHSA-2026:59362nginx@1:1.20.1-13.el92:1.20.1-28.el9_8.5
MediumRHSA-2026:59490nginx@1:1.20.1-13.el91:1.24.0-7.module+el9.8.0+24626+085354fc.4
MediumRHSA-2026:59496nginx@1:1.20.1-13.el92:1.26.3-9.module+el9.8.0+24599+8fde0ff7.3
MediumRHSA-2023:0335dbus@1:1.12.20-6.el91:1.12.20-7.el9_1
MediumRHSA-2026:28254libxml2@2.9.13-2.el90:2.9.13-14.el9_8.1
MediumALPINE-CVE-2023-27537curl@7.80.0-r18.0.1-r0
MediumRHSA-2026:41948javapackages-tools@5.3.0-1.module+el8+2447+6f56d9a60:5.3.0-2.module+el8.10.0+23274+27840b45
MediumRHSA-2024:0256python3@3.6.8-48.el8_70:3.6.8-56.el8_9.3
MediumALPINE-CVE-2023-28321curl@7.80.0-r18.1.0-r0
MediumRHSA-2023:4523curl@7.61.1-25.el80:7.61.1-30.el8_8.3
MediumGHSA-hf6x-8p5f-cgmfhttpcore5@5.0.25.4.3
MediumGHSA-x4gw-5cx5-pgmhnetty-handler@4.1.86.Final4.1.135.Final
MediumRHSA-2025:16116gnutls@3.7.6-12.el9_00:3.8.3-6.el9_6.2
MediumRHSA-2025:17415gnutls@3.6.16-5.el8_60:3.6.16-8.el8_10.4
MediumGHSA-wq8x-cg39-8mrrkeycloak-services@20.0.524.0.9
MediumGHSA-mpwq-j3xf-7m5wkeycloak-services@20.0.523.0.3
MediumGHSA-4fwr-mh5q-hchhquarkus-resteasy@2.13.7.Final3.8.6.1
MediumRHSA-2026:22312openssl@1:3.0.1-43.el9_01:3.5.5-3.el9_8
MediumGHSA-5xp3-jfq3-5q8xpip@9.0.321.1
LowRHSA-2026:1631python3@3.6.8-48.el8_70:3.6.8-72.el8_10
LowGHSA-xfrj-6vvc-3xm2xmlsec@2.2.32.2.6
LowRHSA-2023:4569dbus@1:1.12.20-6.el91:1.12.20-7.el9_2.1
LowRHSA-2026:2786glibc@2.34-40.el90:2.34-231.el9_7.10
LowALPINE-CVE-2023-27535curl@7.80.0-r18.0.1-r0
LowRHSA-2023:2650curl@7.76.1-19.el90:7.76.1-23.el9_2.1
LowRHSA-2026:7668nghttp2@1.43.0-5.el90:1.43.0-6.el9_7.1
LowGHSA-9342-92gg-6v29jakarta.mail@1.6.51.6.8
LowGHSA-cxrx-q234-m22mquarkus-http-core@4.1.95.3.4
LowALPINE-CVE-2023-27536curl@7.80.0-r18.0.1-r0
LowRHSA-2024:10244pam@1.5.1-12.el90:1.5.1-22.el9_5
LowALPINE-CVE-2023-38546curl@7.80.0-r18.4.0-r0
LowGHSA-p5mv-gj8j-xqgfkeycloak-saml-core@20.0.526.6.2
LowGHSA-37gf-gmxv-74wvkeycloak-services@20.0.526.4.9
LowRHSA-2026:16252jq@1.6-3.el80:1.6-12.el8_10
LowRHSA-2026:16693jq@1.6-12.el90:1.6-19.el9_7.0.2
LowRHSA-2026:19365jq@1.6-12.el90:1.6-19.el9_8.2
LowRHSA-2026:11077python3@3.6.8-48.el8_70:3.6.8-76.el8_10
LowRHSA-2025:12876ncurses@6.2-8.20210508.el90:6.2-10.20210508.el9_6.2
LowGHSA-5rxp-2rhr-qwqvkeycloak-services@20.0.522.0.12
LowGHSA-57rv-r2g8-2cj3netty-codec-http@4.1.86.Final4.1.133.Final
LowGHSA-v4mm-q8fv-r2w5wildfly-elytron-realm-token@1.20.1.Finalno fix listed
LowRHSA-2025:22063cups@1:2.2.6-50.el81:2.2.6-64.el8_10
LowRHSA-2026:5080libarchive@3.5.3-3.el90:3.5.3-7.el9_7
LowRHSA-2026:56219python3@3.6.8-48.el8_70:3.6.8-78.el8_10
LowGHSA-qcxp-gm7m-4j5vquarkus-vertx-http@2.13.7.Final3.20.6.2
LowRHSA-2023:4524libcap@2.48-4.el80:2.48-5.el8_8
LowRHSA-2023:5071libcap@2.48-8.el90:2.48-9.el9_2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.7.11latest3 years ago0.11.01411938501,63955,666

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/drogue-iot/drogue-cloud-core.svg)](https://charts.stackradar.io/charts/drogue-iot/drogue-cloud-core)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.