guacamole 1.5.3 Helm chart
helmforgeVerified publisherScored 29 Sept 2026
Apache Guacamole clientless remote desktop gateway with guacd, PostgreSQL or MySQL, OIDC/SAML SSO, and S3 backup
Version 1.5.3 todayapp version 1.6.0 1Artifact Hub
guacamole 1.5.3 deploys 5 container images: library/busybox, guacamole/guacamole, guacamole/guacd and library/postgres. Across them, 886 findings — 2 critical, 2 high. The highest contribution is DEBIAN-CVE-2025-15467 in openssl 3.0.17-1~deb12u2, fixed in 3.0.18-1~deb12u2. Chart.yaml declares kubeVersion >=1.26.0-0; rendered for Kubernetes 1.26.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 1.37 | 0000 | 0 |
| guacamole/ | 1.6.0 | 1158333 | 3,978 |
| guacamole/ | 1.6.0 | 0010 | 23 |
| library/ | 18.6-trixie | 0014134 | 1,320 |
| library/ | 17.5-bookworm | 1154287 | 3,677 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GO-2024-2687 | stdlib | 1.21.9 |
| Medium | DSA-6113-1 | openssl | 3.0.18-1~deb12u2 |
| Medium | DEBIAN-CVE-2019-1010022 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2023-45853 | zlib | no fix listed |
| Medium | DEBIAN-CVE-2017-17740 | openldap | no fix listed |
| Medium | DEBIAN-CVE-2026-45447 | openssl | 3.0.20-1~deb12u2 |
| Medium | DEBIAN-CVE-2018-20796 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2015-3276 | openldap | no fix listed |
| Medium | DEBIAN-CVE-2019-1010023 | glibc | no fix listed |
| Medium | GHSA-r29c-68gh-xp6x | tomcat-coyote | 9.0.118 |
| Medium | GHSA-gqp3-2cvr-x8m3 | tomcat-coyote | 9.0.108 |
| Medium | ALPINE-CVE-2021-27219 | glib | 2.66.6-r0 |
| Medium | DEBIAN-CVE-2025-49796 | libxml2 | 2.9.14+dfsg-1.3~deb12u3 |
| Medium | DEBIAN-CVE-2026-28388 | openssl | 3.0.19-1~deb12u2 |
| Medium | DEBIAN-CVE-2026-28389 | openssl | 3.0.19-1~deb12u2 |
| Medium | DEBIAN-CVE-2019-9192 | glibc | no fix listed |
| Medium | UBUNTU-CVE-2026-8925 | curl | 8.5.0-2ubuntu10.10 |
| Medium | UBUNTU-CVE-2016-20013 | glibc | no fix listed |
| Medium | GHSA-p93r-85wp-75v3 | bcprov-jdk15to18 | 1.80.2 |
| Medium | DEBIAN-CVE-2023-31486 | perl | no fix listed |
| Medium | DEBIAN-CVE-2026-42010 | gnutls28 | 3.7.9-2+deb12u7 |
| Medium | DEBIAN-CVE-2018-5709 | krb5 | no fix listed |
| Medium | UBUNTU-CVE-2025-5987 | libssh | 0.10.6-2ubuntu0.1 |
| Medium | GHSA-25xr-qj8w-c4vf | tomcat-coyote | 9.0.107 |
| Medium | DEBIAN-CVE-2023-31484 | perl | 5.36.0-7+deb12u3 |
| Medium | DEBIAN-CVE-2023-2953 | openldap | no fix listed |
| Medium | GHSA-4j3c-42xv-3f84 | tomcat-coyote | 9.0.107 |
| Medium | DEBIAN-CVE-2026-34182 | openssl | 3.0.20-1~deb12u2 |
| Medium | DEBIAN-CVE-2026-63076 | openssl | 3.0.22-1~deb12u1 |
| Medium | GHSA-8297-v2rf-2p32 | mina-core | 2.2.6 |
| Medium | DEBIAN-CVE-2018-6829 | libgcrypt20 | no fix listed |
| Medium | GHSA-vf5j-865m-mq7c | mina-core | 2.2.7 |
| Medium | GHSA-995c-6rp3-4m4x | mina-core | 2.2.7 |
| Medium | GHSA-f2wh-grmh-r6jm | mina-core | 2.2.6 |
| Medium | DEBIAN-CVE-2026-5450 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2026-33845 | gnutls28 | 3.7.9-2+deb12u7 |
| Medium | DEBIAN-CVE-2025-9230 | openssl | 3.0.17-1~deb12u3 |
| Medium | GHSA-rmj7-2vxq-3g9f | jackson-databind | 2.21.4 |
| Medium | UBUNTU-CVE-2026-11856 | curl | 8.5.0-2ubuntu10.12 |
| Medium | DEBIAN-CVE-2025-49794 | libxml2 | 2.9.14+dfsg-1.3~deb12u3 |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang3 | 3.18.0 |
| Medium | DEBIAN-CVE-2011-3389 | gnutls28 | no fix listed |
| Medium | DEBIAN-CVE-2025-6021 | libxml2 | 2.9.14+dfsg-1.3~deb12u3 |
| Medium | UBUNTU-CVE-2026-10536 | curl | 8.5.0-2ubuntu10.11 |
| Medium | UBUNTU-CVE-2025-59375 | expat | 2.6.1-2ubuntu0.5 |
| Medium | DEBIAN-CVE-2026-34180 | openssl | 3.0.20-1~deb12u2 |
| Medium | DEBIAN-CVE-2026-54874 | openssl | 3.0.22-1~deb12u1 |
| Medium | GHSA-j3rv-43j4-c7qm | jackson-databind | 2.21.4 |
| Medium | DEBIAN-CVE-2026-57433 | perl | no fix listed |
| Medium | DEBIAN-CVE-2025-7424 | libxslt | 1.1.35-1+deb12u2 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.5.3latest | today | 1.6.0 | 22127754 | 8,998 |
| 1.5.2 | 2 days ago | 1.6.0 | 22127754 | 8,998 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.