StackRadar

openbas Helm chart

helm-openbasVerified publisher

Scored 15 Sept 2026

A Helm chart to deploy Open Breach and Attack Simulation platform

Latest 1.8.14 9 months agoapp version 2.0.5 0Artifact Hub

openbas 1.8.14 deploys 7 container images: quay.io/minio/minio, openbas/caldera-server, openbas/platform, opensearchproject/opensearch and 3 more. Across them, 2,236 findings7 critical, 19 high 7 on CISA KEV. The highest contribution is GHSA-83qj-6fr2-vhqg in tomcat-embed-core 10.1.34, fixed in 10.1.35.

Radar Score

25,0997193521,855

2,236 findings over 7 of 7 images measured

KEV ×7 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

7 images
ImageTagVulnerabilitiesRadar Score
quay.io/minio/minioRELEASE.2024-12-18T13-15-44Z01131301,398
openbas/caldera-server5.1.051015784511,816
openbas/platform2.0.524653304,472
opensearchproject/opensearch×23.3.2001143650
bitnamilegacy/postgresql17.6.0-debian-12-r402512173,062
bitnamilegacy/rabbitmq×24.1.2-debian-12-r101461802,616
quay.io/minio/mcRELEASE.2024-11-21T17-21-54Z0191101,085

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

1,121 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGO-2026-4986stdlib@go1.19.81.25.10
LowGHSA-966j-vmvw-g2g9aiohttp@3.10.83.13.4
LowGO-2026-4918stdlib@go1.19.81.25.10
LowGO-2026-4918golang.org/x/net@v0.14.00.53.0
LowGO-2026-4337stdlib@go1.19.81.24.13
LowUBUNTU-CVE-2026-4438glibc@2.39-0ubuntu8.62.39-0ubuntu8.8
LowGHSA-mfg7-5gfp-c4w3netty-codec-dns@4.1.116.Final4.1.136.Final
LowDEBIAN-CVE-2026-59998openssh@1:9.2p1-2+deb12u5no fix listed
LowGHSA-qccp-gfcp-xxvcurllib3@2.3.02.7.0
LowGHSA-5c9x-8gcm-mpgxaxios@0.26.10.31.1
LowGHSA-vf2m-468p-8v99axios@0.26.10.31.1
LowDEBIAN-CVE-2024-28835gnutls28@3.7.9-2+deb12u23.7.9-2+deb12u3
LowDEBIAN-CVE-2023-31438systemd@252.22-1~deb12u1no fix listed
LowDEBIAN-CVE-2026-32288golang-1.19@1.19.8-2no fix listed
LowDEBIAN-CVE-2026-1757libxml2@2.9.14+dfsg-1.3~deb12u22.9.14+dfsg-1.3~deb12u6
LowGHSA-x2r2-rvhq-2mqvspring-security-web@6.3.6no fix listed
LowDEBIAN-CVE-2025-3198binutils@2.40-2no fix listed
LowGHSA-wwpq-f5c3-7hvxspring-boot@3.3.7no fix listed
LowGO-2026-4601stdlib@go1.19.81.25.8
LowGHSA-qx2v-qp2m-jg93postcss@8.4.168.5.10
LowGHSA-fw8g-cg8f-9j28github.com/prometheus/prometheus@v0.300.10.311.3
LowUBUNTU-CVE-2026-72522expat@2.6.1-2ubuntu0.3no fix listed
LowDEBIAN-CVE-2008-3234openssh@1:9.2p1-2+deb12u5no fix listed
LowUBUNTU-CVE-2026-56403expat@2.6.1-2ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-56404expat@2.6.1-2ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-56405expat@2.6.1-2ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-56408expat@2.6.1-2ubuntu0.3no fix listed
LowGHSA-gcjf-9mgh-3p7gnetty-codec-http@4.1.116.Final4.1.136.Final
LowGHSA-v8h7-rr48-vmmvnetty-codec-http@4.1.116.Final4.1.133.Final
LowUBUNTU-CVE-2026-56406expat@2.6.1-2ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-56407expat@2.6.1-2ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-56410expat@2.6.1-2ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-56411expat@2.6.1-2ubuntu0.3no fix listed
LowDEBIAN-CVE-2026-19499glibc@2.36-9+deb12u9no fix listed
LowUBUNTU-CVE-2026-78410util-linux@2.39.3-9ubuntu6.3no fix listed
LowUBUNTU-CVE-2026-58471wget@1.21.4-1ubuntu4.11.21.4-1ubuntu4.3
LowUBUNTU-CVE-2026-58472wget@1.21.4-1ubuntu4.11.21.4-1ubuntu4.3
LowGHSA-563q-j3cm-6jxmnetty-codec-http2@4.1.116.Final4.1.135.Final
LowUBUNTU-CVE-2026-89161pcre2@10.42-4ubuntu2.1no fix listed
LowGHSA-3rh2-v3gr-35p9github.com/minio/minio@v0.0.0-20241218131544-16f8cf1c52f0no fix listed
LowDEBIAN-CVE-2025-4516python3.11@3.11.2-6+deb12u53.11.2-6+deb12u7
LowGO-2026-5026stdlib@go1.19.81.25.13
LowGO-2026-5026golang.org/x/net@v0.14.00.55.0
LowBIT-gdal-2026-8084gdal@3.11.33.13.0
LowDEBIAN-CVE-2025-14104util-linux@2.38.1-5+deb12u1no fix listed
LowUBUNTU-CVE-2025-64505libpng1.6@1.6.43-5build11.6.43-5ubuntu0.1
LowDEBIAN-CVE-2025-6069python3.11@3.11.2-6+deb12u53.11.2-6+deb12u7
LowGHSA-5x3r-wrvg-rp6qnetty-codec-http2@4.1.116.Final4.1.135.Final
LowDEBIAN-CVE-2026-86142libxml2@2.9.14+dfsg-1.3~deb12u2no fix listed
LowUBUNTU-CVE-2026-42014gnutls28@3.8.3-1.1ubuntu3.43.8.3-1.1ubuntu3.6

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.8.14latest9 months ago2.0.57193521,85525,099

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/helm-openbas/openbas.svg)](https://charts.stackradar.io/charts/helm-openbas/openbas)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.