mod-oa Helm chart
folio-orgScored 14 Sept 2026
A Helm chart for Kubernetes
Latest 0.1.2 3 years agodeploys tag latest 0Artifact Hub
mod-oa 0.1.2 deploys 1 container image: folioci/mod-oa. Across them, 135 findings — 0 critical, 4 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.3.1-r3, fixed in 3.3.6-r0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
1 image
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| folioci/ | latest | 043596 | 1,733 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
135 distinct across the version’s images
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | ALPINE-CVE-2025-15467 | openssl | 3.3.6-r0 |
| High | GHSA-4wrc-f8pq-fpqp | spring-web | 6.0.0 |
| High | ALPINE-CVE-2024-6119 | openssl | 3.3.2-r0 |
| High | GHSA-g5vr-rgqm-vf78 | spring-webmvc | no fix listed |
| Medium | GHSA-cx7f-g6mp-7hqm | spring-webmvc | no fix listed |
| Medium | GHSA-57j2-w4cx-62h2 | jackson-databind | 2.12.6.1 |
| Medium | ALPINE-CVE-2024-45492 | expat | 2.6.3-r0 |
| Medium | GHSA-jjjh-jjxp-wpff | jackson-databind | 2.12.7.1 |
| Medium | GHSA-rgv9-q543-rqg4 | jackson-databind | 2.12.7.1 |
| Medium | ALPINE-CVE-2024-45491 | expat | 2.6.3-r0 |
| Medium | ALPINE-CVE-2024-45490 | expat | 2.6.3-r0 |
| Medium | ALPINE-CVE-2025-9230 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2024-12797 | openssl | 3.3.3-r0 |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang3 | 3.18.0 |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang | no fix listed |
| Medium | ALPINE-CVE-2025-9231 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2025-59375 | expat | 2.7.2-r0 |
| Medium | ALPINE-CVE-2024-8176 | expat | 2.7.0-r0 |
| Medium | GHSA-355h-qmc2-wpwf | jetty-http | 9.4.60 |
| Medium | GHSA-f3jh-qvm4-mg39 | spring-security-core | 6.1.8 |
| Medium | ALPINE-CVE-2026-25646 | libpng | 1.6.55-r0 |
| Medium | GHSA-qw69-rqj8-6qw8 | jetty-server | 9.4.51.v20230217 |
| Medium | ALPINE-CVE-2025-13151 | libtasn1 | 4.21.0-r0 |
| Medium | GHSA-3x8x-79m2-3w2w | jackson-databind | 2.12.6 |
| Medium | GHSA-rmj7-2vxq-3g9f | jackson-databind | 2.18.8 |
| Medium | GHSA-2p5w-cvg5-gc5c | hibernate-core | no fix listed |
| Medium | ALPINE-CVE-2024-9143 | openssl | 3.3.2-r1 |
| Medium | GHSA-j3rv-43j4-c7qm | jackson-databind | 2.18.8 |
| Medium | ALPINE-CVE-2026-33416 | libpng | 1.6.56-r0 |
| Medium | GHSA-h46c-h94j-95f3 | jackson-core | 2.15.0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.3.7-r0 |
| Medium | GHSA-r936-gwx5-v52f | spring-webmvc | no fix listed |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.3.6-r0 |
| Medium | GHSA-mf92-479x-3373 | spring-security-web | no fix listed |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.3.7-r0 |
| Low | ALPINE-CVE-2025-69420 | openssl | 3.3.6-r0 |
| Low | GHSA-g3pr-3p32-fp23 | micrometer-core | no fix listed |
| Low | ALPINE-CVE-2026-33636 | libpng | 1.6.56-r0 |
| Low | GHSA-2fvj-hgj9-j2gr | jetty-security | 9.4.63 |
| Low | GHSA-w3w6-26f2-p474 | spring-security-core | 6.1.7 |
| Low | GHSA-3wrr-7qpf-2prh | jackson-databind | 2.14.0 |
| Low | GHSA-mg83-c7gq-rv5c | spring-security-crypto | 5.8.18 |
| Low | ALPINE-CVE-2026-31789 | openssl | 3.3.7-r0 |
| Low | ALPINE-CVE-2025-69419 | openssl | 3.3.6-r0 |
| Low | GHSA-c43q-5hpj-4crv | jersey-common | 2.34 |
| Low | ALPINE-CVE-2024-50602 | expat | 2.6.4-r0 |
Indexed versions
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
[](https://charts.stackradar.io/charts/folio-org/mod-oa)
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.