nacos Helm chart
gujunxiangScored 14 Sept 2026
nacos-k8s
Latest 0.1.5 3 years agodeploys tag latest 2Artifact Hub
nacos 0.1.5 deploys 1 container image: nacos/nacos-server. Across them, 200 findings — 0 critical, 0 high. The highest contribution is GHSA-r29c-68gh-xp6x in tomcat-embed-core 10.1.54, fixed in 10.1.55.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
1 image
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| nacos/ | latest | 0019181 | 1,767 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
200 distinct across the version’s images
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-r29c-68gh-xp6x | tomcat-embed-core | 10.1.55 |
| Medium | GHSA-h6fc-48rj-7qqh | tomcat-embed-core | 10.1.55 |
| Medium | UBUNTU-CVE-2026-19931 | curl | no fix listed |
| Medium | GHSA-5m62-pw8w-7w9f | tomcat-embed-core | 10.1.55 |
| Medium | GHSA-9xv2-5v5q-p794 | tomcat-embed-core | 10.1.58 |
| Medium | UBUNTU-CVE-2026-18924 | curl | no fix listed |
| Medium | GHSA-c459-2m73-67hj | hessian | 3.5.5 |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang | no fix listed |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang3 | 3.18.0 |
| Medium | UBUNTU-CVE-2018-10126 | libjpeg-turbo | no fix listed |
| Medium | GHSA-h3x4-894j-xpx5 | tomcat-embed-core | 10.1.58 |
| Medium | GHSA-rmj7-2vxq-3g9f | jackson-databind | 2.21.4 |
| Medium | GHSA-j3rv-43j4-c7qm | jackson-databind | 2.21.4 |
| Medium | GHSA-gcx9-497g-6cp6 | tomcat-embed-core | 10.1.58 |
| Medium | UBUNTU-CVE-2026-80229 | curl | no fix listed |
| Medium | GHSA-hf6x-8p5f-cgmf | httpcore5 | 5.4.3 |
| Medium | GHSA-v3jc-474w-2wm6 | httpcore5-h2 | 5.4.3 |
| Medium | UBUNTU-CVE-2026-11940 | python3.14 | no fix listed |
| Medium | GHSA-gx5v-xp9w-j4cg | tomcat-embed-core | 10.1.55 |
| Low | UBUNTU-CVE-2026-57433 | perl | 5.40.1-7ubuntu0.3 |
| Low | GHSA-g3pr-3p32-fp23 | micrometer-core | 1.15.12 |
| Low | UBUNTU-CVE-2026-13221 | perl | 5.40.1-7ubuntu0.3 |
| Low | UBUNTU-CVE-2026-66032 | libssh2 | 1.11.1-1ubuntu0.26.04.4 |
| Low | UBUNTU-CVE-2026-82209 | curl | no fix listed |
| Low | UBUNTU-CVE-2026-80255 | curl | no fix listed |
| Low | UBUNTU-CVE-2026-7210 | python3.14 | no fix listed |
| Low | UBUNTU-CVE-2026-12087 | perl | 5.40.1-7ubuntu0.3 |
| Low | UBUNTU-CVE-2026-15308 | python3.14 | 3.14.4-1ubuntu0.2 |
| Low | GHSA-w737-wx49-qj23 | micrometer-core | 1.15.12 |
| Low | UBUNTU-CVE-2026-13608 | curl | no fix listed |
| Low | GHSA-574f-3g2m-x479 | bcprov-jdk18on | 1.80.2 |
| Low | UBUNTU-CVE-2026-66046 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-66033 | libssh2 | 1.11.1-1ubuntu0.26.04.4 |
| Low | UBUNTU-CVE-2026-11972 | python3.14 | no fix listed |
| Low | UBUNTU-CVE-2026-80230 | curl | no fix listed |
| Low | GHSA-fv25-8xcx-gqjc | tomcat-embed-core | 10.1.55 |
| Low | UBUNTU-CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1.1 |
| Low | UBUNTU-CVE-2026-86145 | pcre2 | no fix listed |
| Low | GHSA-qv9r-c865-cp47 | log4j-api | 2.25.5 |
| Low | UBUNTU-CVE-2026-66035 | libssh2 | 1.11.1-1ubuntu0.26.04.4 |
| Low | GHSA-5mp6-jrq3-r938 | tomcat-embed-core | 10.1.55 |
| Low | UBUNTU-CVE-2026-47057 | openjdk-17 | no fix listed |
| Low | UBUNTU-CVE-2026-9538 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-85091 | zlib | no fix listed |
| Low | UBUNTU-CVE-2026-42497 | perl | no fix listed |
| Low | GHSA-c3fc-8qff-9hwx | bcprov-jdk18on | 1.84 |
| Low | GHSA-x23c-287f-qqv5 | spring-webmvc | 6.2.19 |
| Low | UBUNTU-CVE-2026-8932 | curl | 8.18.0-1ubuntu2.5 |
| Low | UBUNTU-CVE-2026-75803 | openssl | 3.5.5-1ubuntu3.5 |
| Low | GHSA-wg6q-6289-32hp | bcpkix-jdk18on | 1.84 |
Indexed versions
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
[](https://charts.stackradar.io/charts/gujunxiang/nacos)
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.