drogue-cloud-core Helm chart
drogue-iotVerified publisherScored 14 Sept 2026
Drogue IoT Cloud core installation
Latest 0.7.11 3 years agoapp version 0.11.0 0Artifact Hub
drogue-cloud-core 0.7.11 deploys 22 container images: bitnami/postgresql, ghcr.io/drogue-iot/mqtt-integration, ghcr.io/drogue-iot/websocket-integration, swaggerapi/swagger-ui and 18 more. Across the 21 measured, 2,823 findings — 141 critical, 193 high — 63 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.80.0-r1, fixed in 8.4.0-r0. Chart.yaml declares kubeVersion >= 1.22.0-0; rendered for Kubernetes 1.22.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-q6cq-mhr2-jmr5 | netty-codec-haproxy | 4.1.136.Final |
| Medium | ALPINE-CVE-2023-1999 | libwebp | 1.2.2-r1 |
| Medium | RHBA-2024:2413 | glibc | 0:2.34-100.el9 |
| Medium | RHSA-2026:59362 | nginx | 2:1.20.1-28.el9_8.5 |
| Medium | RHSA-2026:59490 | nginx | 1:1.24.0-7.module+el9.8.0+24626+085354fc.4 |
| Medium | RHSA-2026:59496 | nginx | 2:1.26.3-9.module+el9.8.0+24599+8fde0ff7.3 |
| Medium | RHSA-2023:0335 | dbus | 1:1.12.20-7.el9_1 |
| Medium | RHSA-2026:28254 | libxml2 | 0:2.9.13-14.el9_8.1 |
| Medium | ALPINE-CVE-2023-27537 | curl | 8.0.1-r0 |
| Medium | RHSA-2026:41948 | javapackages-tools | 0:5.3.0-2.module+el8.10.0+23274+27840b45 |
| Medium | RHSA-2024:0256 | python3 | 0:3.6.8-56.el8_9.3 |
| Medium | ALPINE-CVE-2023-28321 | curl | 8.1.0-r0 |
| Medium | RHSA-2023:4523 | curl | 0:7.61.1-30.el8_8.3 |
| Medium | GHSA-hf6x-8p5f-cgmf | httpcore5 | 5.4.3 |
| Medium | GHSA-x4gw-5cx5-pgmh | netty-handler | 4.1.135.Final |
| Medium | RHSA-2025:16116 | gnutls | 0:3.8.3-6.el9_6.2 |
| Medium | RHSA-2025:17415 | gnutls | 0:3.6.16-8.el8_10.4 |
| Medium | GHSA-wq8x-cg39-8mrr | keycloak-services | 24.0.9 |
| Medium | GHSA-mpwq-j3xf-7m5w | keycloak-services | 23.0.3 |
| Medium | GHSA-4fwr-mh5q-hchh | quarkus-resteasy | 3.8.6.1 |
| Medium | RHSA-2026:22312 | openssl | 1:3.5.5-3.el9_8 |
| Medium | GHSA-5xp3-jfq3-5q8x | pip | 21.1 |
| Low | RHSA-2026:1631 | python3 | 0:3.6.8-72.el8_10 |
| Low | GHSA-xfrj-6vvc-3xm2 | xmlsec | 2.2.6 |
| Low | RHSA-2023:4569 | dbus | 1:1.12.20-7.el9_2.1 |
| Low | RHSA-2026:2786 | glibc | 0:2.34-231.el9_7.10 |
| Low | ALPINE-CVE-2023-27535 | curl | 8.0.1-r0 |
| Low | RHSA-2023:2650 | curl | 0:7.76.1-23.el9_2.1 |
| Low | RHSA-2026:7668 | nghttp2 | 0:1.43.0-6.el9_7.1 |
| Low | GHSA-9342-92gg-6v29 | jakarta.mail | 1.6.8 |
| Low | GHSA-cxrx-q234-m22m | quarkus-http-core | 5.3.4 |
| Low | ALPINE-CVE-2023-27536 | curl | 8.0.1-r0 |
| Low | RHSA-2024:10244 | pam | 0:1.5.1-22.el9_5 |
| Low | ALPINE-CVE-2023-38546 | curl | 8.4.0-r0 |
| Low | GHSA-p5mv-gj8j-xqgf | keycloak-saml-core | 26.6.2 |
| Low | GHSA-37gf-gmxv-74wv | keycloak-services | 26.4.9 |
| Low | RHSA-2026:16252 | jq | 0:1.6-12.el8_10 |
| Low | RHSA-2026:16693 | jq | 0:1.6-19.el9_7.0.2 |
| Low | RHSA-2026:19365 | jq | 0:1.6-19.el9_8.2 |
| Low | RHSA-2026:11077 | python3 | 0:3.6.8-76.el8_10 |
| Low | RHSA-2025:12876 | ncurses | 0:6.2-10.20210508.el9_6.2 |
| Low | GHSA-5rxp-2rhr-qwqv | keycloak-services | 22.0.12 |
| Low | GHSA-57rv-r2g8-2cj3 | netty-codec-http | 4.1.133.Final |
| Low | GHSA-v4mm-q8fv-r2w5 | wildfly-elytron-realm-token | no fix listed |
| Low | RHSA-2025:22063 | cups | 1:2.2.6-64.el8_10 |
| Low | RHSA-2026:5080 | libarchive | 0:3.5.3-7.el9_7 |
| Low | RHSA-2026:56219 | python3 | 0:3.6.8-78.el8_10 |
| Low | GHSA-qcxp-gm7m-4j5v | quarkus-vertx-http | 3.20.6.2 |
| Low | RHSA-2023:4524 | libcap | 0:2.48-5.el8_8 |
| Low | RHSA-2023:5071 | libcap | 0:2.48-9.el9_2 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.7.11latest | 3 years ago | 0.11.0 | 1411938501,639 | 55,666 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.