StackRadar

grocy 8.5.2 Helm chart

geek-cookbookVerified publisher

Scored 14 Sept 2026

ERP beyond your fridge - grocy is a web-based self-hosted groceries & household management solution for your home

Version 8.5.2 4 years agoapp version version-v3.1.3 0Artifact Hub

grocy 8.5.2 deploys 1 container image: linuxserver/grocy. Across them, 58 findings0 critical, 4 high 1 on CISA KEV. The highest contribution is GHSA-jpcq-cgw6-v4j6 in jquery 3.3.1, fixed in 3.5.0. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.

Radar Score

1,043042430

58 findings over 1 of 1 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
linuxserver/grocyversion-v3.1.30424301,043

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

58 distinct across the version’s images
SeverityAdvisoryPackageFixed in
HighGHSA-jpcq-cgw6-v4j6KEVjquery@3.3.13.5.0
HighGHSA-gxr4-xjj5-5px2jquery@3.3.13.5.0
HighGHSA-6c3j-c64m-qhgqjquery@3.3.13.4.0
HighGHSA-r5fr-rjxr-66jclodash@4.17.214.18.0
MediumGHSA-hrpp-h998-j3ppqs@6.5.26.5.3
MediumGHSA-9v3m-8fp8-mj99bootstrap@4.0.04.3.1
MediumGHSA-896r-f27r-55mwjson-schema@0.2.30.4.0
MediumGHSA-8hfj-j24r-96c4moment@2.29.12.29.2
MediumGHSA-wc69-rhjr-hc9gmoment@2.29.12.29.4
MediumGHSA-h68q-55jf-x68wchart.js@2.7.12.9.4
MediumGHSA-446m-mv8f-q348moment@2.18.12.19.3
MediumGHSA-fjxv-7rqg-78g4form-data@2.3.32.5.4
MediumGHSA-m7j4-fhg6-xf5vdatatables.net@1.10.161.10.22
MediumGHSA-pj7m-g53m-7638bootstrap@4.0.04.1.2
MediumGHSA-3wqf-4x89-9g79bootstrap@4.0.04.1.2
MediumGHSA-7mvr-5x2g-wfc8bootstrap@4.0.04.1.2
MediumGHSA-25mq-v84q-4j7rguzzlehttp/guzzle@7.4.07.4.5
MediumGHSA-f2wf-25xc-69c9guzzlehttp/guzzle@7.4.07.4.4
MediumGHSA-w248-ffj2-4v5qguzzlehttp/guzzle@7.4.07.4.4
MediumGHSA-xvf7-4v9q-58w6jpeg-js@0.4.30.4.4
MediumGHSA-72xf-g2v4-qvf3tough-cookie@2.5.04.1.3
MediumGHSA-q559-8m2m-g699guzzlehttp/guzzle@7.4.07.4.5
MediumGHSA-cwmx-hcrq-mhc3guzzlehttp/guzzle@7.4.07.4.3
MediumGHSA-h73q-5wmj-q8pjdatatables.net@1.10.161.11.3
MediumGHSA-f23m-r3pf-42rhlodash@4.17.214.18.0
MediumGHSA-xxjr-mmjv-4gpglodash@4.17.214.17.23
MediumGHSA-q7rv-6hp3-vh96guzzlehttp/psr7@2.1.02.1.1
MediumGHSA-6c9x-mj3g-h47xswagger-ui-dist@3.52.54.1.3
LowGHSA-m4ch-4m5f-2gp6bootbox@5.5.2no fix listed
LowGHSA-hmw2-7cc7-3qxxform-data@2.3.32.5.6
LowGHSA-q2qj-628g-vhfwslim/psr7@1.51.5.1
LowGHSA-66hf-2p6w-jqfwilluminate/view@v8.70.28.75.0
LowGHSA-wxmh-65f7-jcvwguzzlehttp/psr7@2.1.02.4.5
LowGHSA-j3f9-p6hm-5w6qnesbot/carbon@2.54.02.72.6
LowGHSA-2g4f-4pwh-qvx6ajv@6.12.66.14.0
LowGHSA-p8p7-x288-28g6request@2.88.2no fix listed
LowGHSA-w5hq-g745-h8pquuid@3.4.011.1.1
LowGHSA-cc55-mvqc-g9mgsummernote@0.8.20no fix listed
LowGHSA-v5mv-p594-2x33guzzlehttp/guzzle@7.4.07.15.2
LowGHSA-h95v-h523-3mw8guzzlehttp/guzzle@7.4.07.15.1
LowGHSA-wm3w-8rrp-j577guzzlehttp/guzzle@7.4.07.15.1
LowGHSA-cwxw-98qj-8qjxguzzlehttp/guzzle@7.4.07.12.1
LowGHSA-4mjr-xmp4-gh2gqs@6.5.26.16.0
LowGHSA-53h4-8rc4-f539slim/slim@4.9.04.15.2
LowGHSA-f7vp-7xgx-4w4rguzzlehttp/guzzle@7.4.07.15.2
LowGHSA-f283-ghqc-fg79guzzlehttp/guzzle@7.4.07.15.1
LowGHSA-94pj-82f3-465wguzzlehttp/guzzle@7.4.07.14.2
LowGHSA-wpwq-4j6v-78m3guzzlehttp/guzzle@7.4.07.12.1
LowGHSA-34xg-wgjx-8xphguzzlehttp/psr7@2.1.02.10.2
LowGHSA-hq7v-mx3g-29hwguzzlehttp/psr7@2.1.02.10.2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
8.5.2latest4 years agoversion-v3.1.30424301,043

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/geek-cookbook/grocy.svg)](https://charts.stackradar.io/charts/geek-cookbook/grocy)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.