nacos Helm chart
gujunxiangScored 14 Sept 2026
nacos-k8s
Latest 0.1.5 3 years agodeploys tag latest 2Artifact Hub
nacos 0.1.5 deploys 1 container image: nacos/nacos-server. Across them, 200 findings — 0 critical, 0 high. The highest contribution is GHSA-r29c-68gh-xp6x in tomcat-embed-core 10.1.54, fixed in 10.1.55.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
1 image
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| nacos/ | latest | 0019181 | 1,767 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
200 distinct across the version’s images
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2026-53612 | util-linux | 2.41.3-3ubuntu2.2 |
| Low | UBUNTU-CVE-2026-53613 | util-linux | 2.41.3-3ubuntu2.2 |
| Low | UBUNTU-CVE-2026-53614 | util-linux | 2.41.3-3ubuntu2.2 |
| Low | UBUNTU-CVE-2026-53615 | util-linux | 2.41.3-3ubuntu2.2 |
| Low | UBUNTU-CVE-2026-77117 | glibc | 2.43-2ubuntu2.4 |
| Low | UBUNTU-CVE-2026-80489 | glibc | 2.43-2ubuntu2.4 |
| Low | GHSA-659m-px2c-25wj | spring-core | 6.2.19 |
| Low | UBUNTU-CVE-2026-35345 | rust-coreutils | no fix listed |
| Low | GHSA-ggg2-9786-hwc8 | spring-boot-autoconfigure | 3.5.15 |
| Low | UBUNTU-CVE-2026-42250 | bzip2 | 1.0.8-6ubuntu0.1 |
| Low | UBUNTU-CVE-2026-32777 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-39113 | sqlite3 | no fix listed |
| Low | UBUNTU-CVE-2026-60589 | openjdk-17 | no fix listed |
| Low | UBUNTU-CVE-2026-76957 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2.2 |
| Low | UBUNTU-CVE-2026-18508 | tar | no fix listed |
| Low | UBUNTU-CVE-2026-45186 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-35359 | rust-coreutils | no fix listed |
| Low | GHSA-h3qp-gqrc-q736 | spring-webmvc | 6.2.19 |
| Low | UBUNTU-CVE-2026-32776 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-35351 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-41080 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-35354 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-35357 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-35370 | rust-coreutils | no fix listed |
| Low | GHSA-7m2p-62gw-p8qq | spring-web | 6.2.19 |
| Low | GHSA-9f52-rjqv-25qv | spring-expression | 6.2.19 |
| Low | UBUNTU-CVE-2026-18477 | tar | no fix listed |
| Low | RUSTSEC-2026-0173 | proc-macro-error2 | no fix listed |
| Low | RUSTSEC-2026-0186 | memmap2 | 0.9.11 |
| Low | RUSTSEC-2026-0204 | crossbeam-epoch | 0.9.20 |
| Low | RUSTSEC-2026-0221 | event-listener | 5.4.2 |
| Low | RUSTSEC-2026-0258 | h2 | 0.4.16 |
| Low | USN-8688-2 | pam | 1.7.0-5ubuntu3.2 |
| Low | UBUNTU-CVE-2026-27171 | zlib | 1:1.3.dfsg+really1.3.1-1ubuntu3.1 |
| Low | UBUNTU-CVE-2025-66382 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-35371 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-35373 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-40228 | systemd | no fix listed |
| Low | UBUNTU-CVE-2026-32778 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-35344 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-35367 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-35377 | rust-coreutils | no fix listed |
| Low | UBUNTU-CVE-2026-57062 | gnupg2 | 2.4.8-4ubuntu3.1 |
| Low | GHSA-p47f-322f-whfh | logback-core | 1.5.33 |
| Low | UBUNTU-CVE-2026-15310 | python3.14 | no fix listed |
| Low | UBUNTU-CVE-2026-53910 | diffutils | 1:3.12-1ubuntu0.1 |
| Low | UBUNTU-CVE-2026-6879 | python3.14 | no fix listed |
| Low | UBUNTU-CVE-2026-18503 | python3.14 | no fix listed |
| Low | UBUNTU-CVE-2026-6368 | glibc | 2.43-2ubuntu2.4 |
Indexed versions
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
[](https://charts.stackradar.io/charts/gujunxiang/nacos)
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.