StackRadar

galoy-pay 0.11.48 Helm chart

galoymoney

Scored 14 Sept 2026

A Helm chart for the admin panel addon to Galoy

Version 0.11.48 1 year agoapp version 0.6.23 (not verified against the render) 0Artifact Hub

galoy-pay 0.11.48 deploys 2 container images: krtk6160/galoy-nostr and us.gcr.io/galoy-org/galoy-pay. Across the 1 measured, 151 findings2 critical, 7 high 1 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.87.0-r2, fixed in 8.4.0-r0.

Radar Score

2,528275290

151 findings over 1 of 2 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
krtk6160/galoy-nostrdigest-pinned2752902,528
us.gcr.io/galoy-org/galoy-paydigest-pinnedunmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

90 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2025-69420openssl@3.0.8-r03.0.19-r0
LowGHSA-rhx6-c78j-4q9wpath-to-regexp@0.1.70.1.12
LowALPINE-CVE-2023-27535curl@7.87.0-r27.88.1-r1
LowALPINE-CVE-2023-27536curl@7.87.0-r27.88.1-r1
LowALPINE-CVE-2023-38546curl@7.87.0-r28.4.0-r0
LowGHSA-34x7-hfp2-rc4vtar@6.1.137.5.7
LowGHSA-xq7p-g2vc-g82pbase-x@3.0.93.0.11
LowGHSA-685m-2w69-288qprotobufjs@7.2.27.5.6
LowGHSA-75px-5xx7-5xc7protobufjs@7.2.27.5.6
LowGHSA-rgw5-rvv9-x895brace-expansion@2.0.12.1.4
LowGHSA-5375-pq7m-f5r2@grpc/grpc-js@1.8.81.9.16
LowGHSA-f5x3-32g6-xq36tar@6.1.136.2.1
LowGHSA-qffp-2rhf-9h96tar@6.1.137.5.10
LowALPINE-CVE-2023-0466openssl@3.0.8-r03.0.8-r3
LowALPINE-CVE-2023-0465openssl@3.0.8-r03.0.8-r2
LowGHSA-23hp-3jrh-7fpwtar@6.1.137.5.19
LowALPINE-CVE-2025-69419openssl@3.0.8-r03.0.19-r0
LowGHSA-hmw2-7cc7-3qxxform-data@2.5.12.5.6
LowGHSA-7r86-cg39-jmmjminimatch@5.1.05.1.8
LowALPINE-CVE-2024-50602expat@2.5.0-r02.6.4-r0
LowGHSA-8qq5-rm4j-mr97tar@6.1.137.5.3
LowALPINE-CVE-2023-27538curl@7.87.0-r27.88.1-r1
LowGHSA-23c5-xmqv-rm74minimatch@5.1.05.1.8
LowGHSA-mh99-v99m-4gvgbrace-expansion@2.0.12.1.3
LowALPINE-CVE-2023-1255openssl@3.0.8-r03.0.8-r4
LowGHSA-wcpc-wj8m-hjx6protobufjs@7.2.27.6.1
LowGHSA-73rr-hh4g-fpgxdiff@5.1.05.2.2
LowGHSA-66ff-xgx4-vchmprotobufjs@7.2.27.5.6
LowGHSA-8x88-c5mf-7j5wtar@6.1.137.5.18
LowALPINE-CVE-2024-6923python3@3.10.10-r03.10.15-r0
LowGHSA-rv95-896h-c2vcexpress@4.18.24.19.2
LowALPINE-CVE-2023-46219curl@7.87.0-r28.5.0-r0
LowALPINE-CVE-2024-4603openssl@3.0.8-r03.0.13-r0
LowALPINE-CVE-2024-0853curl@7.87.0-r28.6.0-r0
LowGHSA-r6q2-hw4h-h46wtar@6.1.137.5.4
LowGHSA-r292-9mhp-454mtar@6.1.137.5.21
LowGHSA-jvwf-75h9-cwggprotobufjs@7.2.27.5.6
LowALPINE-CVE-2023-6597python3@3.10.10-r03.10.14-r0
LowGHSA-w4pp-8pjf-rmxwpacote@15.0.721.5.1
LowGHSA-9ppj-qmqm-q256tar@6.1.137.5.11
LowALPINE-CVE-2025-26519musl@1.2.3-r41.2.3-r6
LowALPINE-CVE-2023-40217python3@3.10.10-r03.10.13-r0
LowGHSA-f886-m6hf-6m8vbrace-expansion@2.0.12.0.3
LowALPINE-CVE-2023-28322curl@7.87.0-r28.1.0-r0
LowGHSA-2w8x-224x-785msjcl@1.0.81.0.9
LowGHSA-83g3-92jg-28cxtar@6.1.137.5.8
LowGHSA-7v5v-9h63-cj86@grpc/grpc-js@1.8.81.8.22
LowGHSA-w8wr-v893-vjvptar@6.1.137.5.18
LowALPINE-CVE-2023-2975openssl@3.0.8-r03.0.9-r2
LowALPINE-CVE-2024-0450python3@3.10.10-r03.10.14-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.11.48latest1 year ago0.6.232752902,528

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/galoymoney/galoy-pay.svg)](https://charts.stackradar.io/charts/galoymoney/galoy-pay)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.