pimcore 2.0.4 Helm chart
helmforgeVerified publisherScored 7 Oct 2026
Pimcore data and experience management platform with PHP-FPM, Messenger workers, and maintenance automation
Version 2.0.4 todaydeploys tag v0.24.2 0Artifact Hub
pimcore 2.0.4 deploys 6 container images: dunglas/mercure, pimcore/pimcore, library/busybox, library/nginx and 2 more. Across the 5 measured, 294 findings — 0 critical, 0 high. The highest contribution is ALPINE-CVE-2026-45447 in openssl 3.5.6-r0, fixed in 3.5.7-r0. Chart.yaml declares kubeVersion >=1.26.0-0; rendered for Kubernetes 1.26.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| dunglas/ | v0.24.2 | 002677 | 1,280 |
| pimcore/ | php8.5.9-max-v5.2-hardened | — | not yet scanned |
| library/ | 1.37.0 | 0000 | 0 |
| library/ | 1.30.4-alpine3.24 | 0017 | 86 |
| library/ | 13.0.2 | 0011171 | 1,688 |
| library/ | 4.3.6-alpine | 0010 | 15 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | ALPINE-CVE-2026-45447 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-8925 | curl | 8.22.0-r0 |
| Medium | GO-2026-4341 | stdlib | 1.24.12 |
| Medium | ALPINE-CVE-2026-34182 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-19931 | curl | 8.22.0-r0 |
| Medium | GO-2026-4337 | stdlib | 1.24.13 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-11856 | curl | 8.22.0-r0 |
| Medium | GO-2026-5026 | stdlib | 1.25.13 |
| Medium | ALPINE-CVE-2026-10536 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-34180 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-9079 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-8924 | curl | 8.22.0-r0 |
| Medium | UBUNTU-CVE-2026-60082 | libdbi-perl | no fix listed |
| Medium | ALPINE-CVE-2026-34183 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-18924 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | GHSA-2v4p-qf9q-27wj | google.golang.org/ | 1.82.2 |
| Medium | ALPINE-CVE-2026-9076 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-3805 | curl | 8.19.0-r0 |
| Medium | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Medium | UBUNTU-CVE-2026-78030 | libdbi-perl | no fix listed |
| Medium | UBUNTU-CVE-2026-14739 | libdbi-perl | no fix listed |
| Medium | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-80231 | curl | 8.22.0-r0 |
| Medium | UBUNTU-CVE-2026-53791 | rsync | no fix listed |
| Medium | ALPINE-CVE-2026-8927 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-7383 | openssl | 3.5.7-r0 |
| Medium | UBUNTU-CVE-2026-15043 | libdbi-perl | no fix listed |
| Medium | ALPINE-CVE-2026-33630 | c-ares | 1.34.8-r0 |
| Medium | GO-2026-4601 | stdlib | 1.25.8 |
| Medium | GO-2026-4981 | stdlib | 1.25.10 |
| Medium | UBUNTU-CVE-2026-14380 | libdbi-perl | no fix listed |
| Medium | ALPINE-CVE-2026-85091 | zlib | 1.3.2-r1 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.0.4latest | today | v0.24.2 | 0039255 | 3,069 |
| 2.0.3 | 5 days ago | v0.24.2 | 0041269 | 3,215 |
| 2.0.2 | 10 days ago | v0.24.2 | 0058262 | 3,552 |
| 2.0.1 | 11 days ago | v0.24.2 | 0058262 | 3,552 |
| 2.0.0 | 28 days ago | v0.24.2 | 0060296 | 3,882 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.