gluu Helm chart
gluu-flexOfficialVerified publisherScored 14 Sept 2026
Gluu Access and Identity Management
Latest 0.0.0-nightly todayapp version 0.0.0-nightly 1Artifact Hub
gluu 0.0.0-nightly deploys 9 container images: ghcr.io/gluufederation/flex/admin-ui, ghcr.io/janssenproject/jans/auth-server, ghcr.io/janssenproject/jans/casa, ghcr.io/janssenproject/jans/config-api and 5 more. Across them, 109 findings — 1 critical, 0 high. The highest contribution is GHSA-f58c-gq56-vjjf in tika-core 2.9.2, fixed in 3.2.2. Chart.yaml declares kubeVersion >=v1.23.0-0; rendered for Kubernetes 1.23.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | 0.0.0-nightly | 0004 | 39 |
| ghcr.io/ | 0.0.0-nightly | 00115 | 200 |
| ghcr.io/ | 0.0.0-nightly | 00311 | 181 |
| ghcr.io/ | 0.0.0-nightly | 10114 | 287 |
| ghcr.io/ | 0.0.0-nightly | 00113 | 178 |
| ghcr.io/ | 0.0.0-nightly | 00113 | 178 |
| ghcr.io/ | 0.0.0-nightly | 0002 | 22 |
| ghcr.io/ | 0.0.0-nightly | 001017 | 400 |
| ghcr.io/ | 0.0.0-nightly | 0002 | 22 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | ALPINE-CVE-2026-8926 | curl | 8.22.0-r0 |
| Low | GHSA-9342-92gg-6v29 | jakarta.mail | 1.6.8 |
| Low | GHSA-2fvj-hgj9-j2gr | jetty-ee9-security | 12.1.10 |
| Low | GHSA-2fvj-hgj9-j2gr | jetty-ee8-security | 12.1.10 |
| Low | GHSA-2fvj-hgj9-j2gr | jetty-security | 12.1.10 |
| Low | ALPINE-CVE-2026-11352 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-82209 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-80255 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-11564 | curl | 8.22.0-r0 |
| Low | GHSA-vp6r-9m58-5xv8 | omnifaces | 4.7.5 |
| Low | ALPINE-CVE-2026-13608 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-11586 | curl | 8.22.0-r0 |
| Low | GHSA-574f-3g2m-x479 | bcprov-jdk18on | 1.80.2 |
| Low | ALPINE-CVE-2026-80230 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-9546 | curl | 8.22.0-r0 |
| Low | GHSA-qv9r-c865-cp47 | log4j-api | 2.25.5 |
| Low | GHSA-373j-mhpf-84wg | jans-config-api-server | 1.8.0 |
| Low | ALPINE-CVE-2026-82208 | curl | 8.22.0-r0 |
| Low | GHSA-c3fc-8qff-9hwx | bcprov-jdk18on | 1.84 |
| Low | ALPINE-CVE-2026-12064 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-8932 | curl | 8.22.0-r0 |
| Low | GHSA-jwv3-5hgf-82ww | cryptography | 49.0.0 |
| Low | ALPINE-CVE-2026-8286 | curl | 8.22.0-r0 |
| Low | GHSA-wg6q-6289-32hp | bcpkix-jdk18on | 1.84 |
| Low | ALPINE-CVE-2026-8458 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-9547 | curl | 8.22.0-r0 |
| Low | GHSA-j92g-9f8w-j867 | postgresql | 42.7.12 |
| Low | ALPINE-CVE-2026-9080 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-9545 | curl | 8.22.0-r0 |
| Low | GHSA-m2h6-j472-rp4c | cryptography | 49.0.0 |
| Low | GHSA-f4v5-65jj-pcr2 | jetty-server | 12.1.10 |
| Low | GHSA-g6cj-pr64-35w5 | cryptography | 50.0.0 |
| Low | GHSA-hjcp-jmpx-g3qm | httpclient5 | 5.6.3 |
| Low | GHSA-337m-mw94-2v6g | commons-configuration2 | 2.15.0 |
| Low | GHSA-w7x5-g22v-xqhr | jetty-util | 12.1.9 |
| Low | GHSA-7p3p-8qv8-m2vh | jetty-server | 12.1.9 |
| Low | GHSA-537c-gmf6-5ccf | cryptography | 48.0.1 |
| Low | GHSA-fp43-vj7g-pg92 | omnifaces | 4.7.12 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.0.0-nightlylatest | today | 0.0.0-nightly | 101791 | 1,507 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.