StackRadar

kube-ecp-stack Helm chart

emqx-operator

Scored 14 Sept 2026

A Helm chart stack for EMQX ECP

Latest 2.5.1 11 days agoapp version 2.5.1 0Artifact Hub

kube-ecp-stack 2.5.1 deploys 16 container images: quay.io/jetstack/cert-manager-cainjector, quay.io/jetstack/cert-manager-controller, quay.io/jetstack/cert-manager-webhook, emqx/neuronex-operator and 12 more. Across the 14 measured, 2,257 findings9 critical, 22 high 4 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 8.1.2-r0, fixed in 8.4.0-r0.

Radar Score

23,6859223251,901

2,257 findings over 14 of 16 images measured

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

16 images
ImageTagVulnerabilitiesRadar Score
quay.io/jetstack/cert-manager-cainjectorv1.16.100887794
quay.io/jetstack/cert-manager-controllerv1.16.1009100935
quay.io/jetstack/cert-manager-webhookv1.16.100994878
emqx/neuronex-operator0.1.0-rc.8unmeasured
emqxecp/otelcol2.5.002231321,566
quay.io/prometheus/pushgatewayv1.10.000989825
quay.io/prometheus-operator/prometheus-config-reloaderv0.78.100991837
quay.io/prometheus/prometheusv2.55.100111081,008
emqx/ecp-emqx-agent-downloader2.5.101181091,216
emqx/emqx4.4.192452541
library/telegraf1.27510833976,062
bitnami/postgresql17.1.0-debian-12-r0unmeasured
datalayers/datalayersv2.2.1004381282,096
emqx/ecp-ui2.5.121823434,868
emqx/ecp-main2.5.100131341,265
quay.io/jetstack/cert-manager-startupapicheckv1.16.100887794

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

778 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.4.121.7.8
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs@v1.20.91.65.0
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/service/kinesis@v1.18.21.43.5
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/service/s3@v1.35.01.97.3
LowDEBIAN-CVE-2026-58055nghttp2@1.52.0-1+deb12u2no fix listed
LowDEBIAN-CVE-2023-26965tiff@4.5.0-6+deb12u14.5.0-6+deb12u2
LowDEBIAN-CVE-2026-7010perl@5.36.0-7+deb12u1no fix listed
LowUBUNTU-CVE-2026-19487perl@5.34.0-3ubuntu1.35.34.0-3ubuntu1.9
LowDEBIAN-CVE-2026-22801libpng1.6@1.6.39-21.6.39-2+deb12u2
LowDEBIAN-CVE-2023-52426expat@2.5.0-1+deb12u1no fix listed
LowDEBIAN-CVE-2026-52492tiff@4.5.0-6+deb12u1no fix listed
LowGHSA-9m57-25v3-79x9golang.org/x/crypto@v0.27.00.52.0
LowGHSA-pwhc-rpq9-4c8wgithub.com/containerd/containerd@v1.7.31.7.29
LowDEBIAN-CVE-2026-89158pcre2@10.42-110.42-1+deb12u1
LowGHSA-x86f-5xw2-fm2rgithub.com/docker/docker@v27.3.1+incompatibleno fix listed
LowGO-2023-2041stdlib@go1.20.71.20.8
LowDEBIAN-CVE-2025-27587openssl@3.0.15-1~deb12u1no fix listed
LowGHSA-vffh-x6r8-xx99github.com/prometheus/prometheus@v0.55.00.311.2-0.20260410083055-07c6232d159b
LowGO-2023-2043stdlib@go1.20.71.20.8
LowDEBIAN-CVE-2013-4392systemd@252.31-1~deb12u1no fix listed
LowGO-2023-2186stdlib@go1.20.71.20.11
LowGHSA-32fw-gq77-f2f2github.com/eclipse/paho.mqtt.golang@v1.4.11.5.1
LowGO-2024-3333golang.org/x/net@v0.29.00.33.0
LowGHSA-9h8m-3fm2-qjrqgo.opentelemetry.io/otel/sdk@v1.28.01.40.0
LowUBUNTU-CVE-2026-78408util-linux@2.37.2-4ubuntu3.4no fix listed
LowGHSA-pwx7-fx9r-hr4hgithub.com/nats-io/nats-server/v2@v2.9.92.11.15
LowUBUNTU-CVE-2026-41989libgcrypt20@1.9.4-3ubuntu31.9.4-3ubuntu3.2
LowDEBIAN-CVE-2026-49271libheif@1.15.1-1+deb12u1no fix listed
LowDEBIAN-CVE-2024-11053curl@7.88.1-10+deb12u87.88.1-10+deb12u10
LowGHSA-2464-8j7c-4cjmgithub.com/go-viper/mapstructure/v2@v2.1.02.4.0
LowGO-2024-3105stdlib@go1.22.01.22.7
LowDEBIAN-CVE-2023-3164tiff@4.5.0-6+deb12u1no fix listed
LowUBUNTU-CVE-2026-13595util-linux@2.37.2-4ubuntu3.42.37.2-4ubuntu3.6
LowGHSA-m6hq-p25p-ffr2github.com/containerd/containerd@v1.7.31.7.29
LowGO-2026-4981stdlib@go1.23.21.25.10
LowDEBIAN-CVE-2023-31439systemd@252.31-1~deb12u1no fix listed
LowGO-2025-3563stdlib@go1.23.21.23.8
LowGO-2026-4977stdlib@go1.23.21.25.10
LowGO-2024-2610stdlib@go1.22.01.21.8
LowDEBIAN-CVE-2026-76957expat@2.5.0-1+deb12u12.5.0-1+deb12u3
LowDEBIAN-CVE-2023-31437systemd@252.31-1~deb12u1no fix listed
LowDEBIAN-CVE-2026-16599wget@1.21.3-1+b2no fix listed
LowGO-2026-4986stdlib@go1.23.21.25.10
LowGO-2026-4918stdlib@go1.23.21.25.10
LowGO-2026-4918golang.org/x/net@v0.29.00.53.0
LowGO-2026-4337stdlib@go1.23.21.24.13
LowDEBIAN-CVE-2026-4438glibc@2.36-9+deb12u92.36-9+deb12u14
LowGHSA-44p7-9xx4-hf2ggolang.org/x/image@v0.18.00.38.0
LowDEBIAN-CVE-2024-28835gnutls28@3.7.9-2+deb12u23.7.9-2+deb12u3
LowDEBIAN-CVE-2023-31438systemd@252.31-1~deb12u1no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.5.1latest11 days ago2.5.19223251,90123,685

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/emqx-operator/kube-ecp-stack.svg)](https://charts.stackradar.io/charts/emqx-operator/kube-ecp-stack)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.