openaev 2.0.11 Helm chart
helm-openbasVerified publisherScored 8 Oct 2026
A Helm chart to deploy Open Breach and Attack Simulation platform
Version 2.0.11 todayapp version 3.261005.0 0Artifact Hub
openaev 2.0.11 deploys 7 container images: library/busybox, rustfs/rustfs, openbas/caldera-server, openaev/platform and 3 more. Across the 6 measured, 1,780 findings — 9 critical, 10 high — 4 on CISA KEV. The highest contribution is DSA-5880-1 in freetype 2.12.1+dfsg-5+deb12u3, fixed in 2.12.1+dfsg-5+deb12u4.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | stable | 0000 | 0 |
| rustfs/ | 1.0.1 | 0010 | 15 |
| openbas/ | 5.1.0 | 79222844 | 13,455 |
| openaev/ | 3.261005.0 | 0011113 | 1,113 |
| opensearchproject/ | 3.9.0 | — | not yet scanned |
| bitnamilegacy/ | 17.6.0-debian-12-r4 | 1157226 | 3,332 |
| bitnamilegacy/ | 4.1.2-debian-12-r1 | 1052233 | 3,205 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | DEBIAN-CVE-2026-8924 | curl | no fix listed |
| Medium | GHSA-pjwm-pj3p-43mv | axios | 0.32.0 |
| Medium | GHSA-9qf2-26p9-2q2q | spring-webflux | no fix listed |
| Medium | DEBIAN-CVE-2023-6277 | tiff | no fix listed |
| Medium | DEBIAN-CVE-2025-13151 | libtasn1-6 | no fix listed |
| Medium | GO-2022-1038 | stdlib | 1.18.7 |
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | DEBIAN-CVE-2025-0725 | curl | no fix listed |
| Medium | DEBIAN-CVE-2026-66046 | expat | 2.5.0-1+deb12u4 |
| Medium | GHSA-2xpw-w6gg-jr37 | urllib3 | 2.6.0 |
| Medium | GHSA-gm62-xv2j-4w53 | urllib3 | 2.6.0 |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Medium | DEBIAN-CVE-2026-52490 | tiff | no fix listed |
| Medium | DEBIAN-CVE-2023-45285 | golang-1.19 | no fix listed |
| Medium | UBUNTU-CVE-2026-42009 | gnutls28 | 3.8.3-1.1ubuntu3.6+Fips1.2 |
| Medium | DEBIAN-CVE-2024-26461 | krb5 | no fix listed |
| Medium | DEBIAN-CVE-2024-34156 | golang-1.19 | no fix listed |
| Medium | GO-2024-3106 | stdlib | 1.22.7 |
| Medium | DEBIAN-CVE-2019-1010024 | glibc | no fix listed |
| Medium | UBUNTU-CVE-2026-33846 | gnutls28 | 3.8.3-1.1ubuntu3.6+Fips1.2 |
| Medium | GO-2023-1570 | stdlib | 1.19.6 |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | BIT-postgresql-2026-16239 | postgresql | 14.24.0 |
| Medium | DEBIAN-CVE-2025-32990 | gnutls28 | 3.7.9-2+deb12u5 |
| Medium | DEBIAN-CVE-2026-8376 | perl | 5.36.0-7+deb12u4 |
| Medium | BIT-postgresql-2026-14669 | postgresql | 14.24.0 |
| Medium | DEBIAN-CVE-2026-27140 | golang-1.19 | no fix listed |
| Medium | DEBIAN-CVE-2026-33416 | libpng1.6 | 1.6.39-2+deb12u4 |
| Medium | DEBIAN-CVE-2024-24784 | golang-1.19 | no fix listed |
| Medium | GO-2024-2609 | stdlib | 1.21.8 |
| Medium | DEBIAN-CVE-2024-34158 | golang-1.19 | no fix listed |
| Medium | GO-2024-3107 | stdlib | 1.22.7 |
| Medium | DEBIAN-CVE-2026-18924 | curl | no fix listed |
| Medium | GHSA-p782-xgp4-8hr8 | golang.org/ | 0.0.0-20220412211240-33da011f77ad |
| Medium | GO-2022-0493 | stdlib | 1.17.10 |
| Medium | DSA-5895-1 | xz-utils | 5.4.1-1 |
| Medium | DEBIAN-CVE-2026-31790 | openssl | 3.0.19-1~deb12u2 |
| Medium | DEBIAN-CVE-2024-2379 | curl | no fix listed |
| Medium | DEBIAN-CVE-2020-14145 | openssh | no fix listed |
| Medium | GHSA-p92q-9vqr-4j8v | axios | 0.32.0 |
| Medium | GHSA-67hx-6x53-jw92 | @babel/ | 7.23.2 |
| Medium | GHSA-25h7-pfq9-p65f | flatted | 3.4.0 |
| Medium | DEBIAN-CVE-2025-9232 | openssl | 3.0.17-1~deb12u3 |
| Medium | DEBIAN-CVE-2026-9076 | openssl | 3.0.20-1~deb12u2 |
| Medium | GHSA-62hf-57xw-28j9 | axios | 0.31.1 |
| Medium | GHSA-hfxv-24rg-xrqf | axios | 0.32.0 |
| Medium | UBUNTU-CVE-2018-18064 | cairo | no fix listed |
| Medium | DEBIAN-CVE-2025-69421 | openssl | 3.0.18-1~deb12u2 |
| Medium | DEBIAN-CVE-2023-24539 | golang-1.19 | no fix listed |
| Medium | DEBIAN-CVE-2023-29400 | golang-1.19 | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.0.11latest | today | 3.261005.0 | 9103431,416 | 21,120 |
| 2.0.10 | 3 days ago | 3.261001.0 | 21118571 | 7,600 |
| 2.0.9 | 6 days ago | 3.261001.0 | 21117572 | 7,594 |
| 2.0.8 | 11 days ago | 3.260923.0 | 21127614 | 8,178 |
| 2.0.7 | 16 days ago | 3.260921.0 | 21128605 | 8,185 |
| 2.0.6 | 18 days ago | 3.260917.1 | 21128596 | 8,083 |
| 2.0.5 | 1 month ago | 3.260904.0 | 21129634 | 8,415 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.