StackRadar

tomcat Helm chart

helmforgeVerified publisher

Scored 14 Sept 2026

Apache Tomcat Helm chart with official image, Gateway API, JMX, and production controls

Latest 1.0.6 2 days agoapp version 11.0.25 0Artifact Hub

tomcat 1.0.6 deploys 2 container images: library/tomcat and library/busybox. Across them, 139 findings0 critical, 0 high. The highest contribution is UBUNTU-CVE-2026-19931 in curl 8.5.0-2ubuntu10.12, with no fix listed. Chart.yaml declares kubeVersion >=1.26.0-0; rendered for Kubernetes 1.26.0.

Radar Score

1,1850010128

139 findings over 2 of 2 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
library/tomcat×211.0.25-jdk17-temurin-noble00101281,185
library/busybox1.3700000

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

128 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2026-77117glibc@2.39-0ubuntu8.82.39-0ubuntu8.9
LowUBUNTU-CVE-2026-80489glibc@2.39-0ubuntu8.82.39-0ubuntu8.9
LowUBUNTU-CVE-2025-69644binutils@2.42-4ubuntu2.10no fix listed
LowUBUNTU-CVE-2026-59845libssh@0.10.6-2ubuntu0.40.10.6-2ubuntu0.5
LowUBUNTU-CVE-2026-42250bzip2@1.0.8-5.1build0.11.0.8-5.1ubuntu0.1
LowUBUNTU-CVE-2026-32777expat@2.6.1-2ubuntu0.4no fix listed
LowUBUNTU-CVE-2026-39113sqlite3@3.45.1-1ubuntu2.7no fix listed
LowUBUNTU-CVE-2026-76957expat@2.6.1-2ubuntu0.4no fix listed
LowUBUNTU-CVE-2026-27456util-linux@2.39.3-9ubuntu6.52.39.3-9ubuntu6.6
LowUBUNTU-CVE-2026-18508tar@1.35+dfsg-3ubuntu0.4no fix listed
LowUBUNTU-CVE-2026-41990libgcrypt20@1.10.3-2ubuntu0.11.12.0-2ubuntu0.1~Fips1~rc11
LowUBUNTU-CVE-2026-45186expat@2.6.1-2ubuntu0.4no fix listed
LowUBUNTU-CVE-2022-3219gnupg2@2.4.4-2ubuntu17.4no fix listed
LowUBUNTU-CVE-2026-32776expat@2.6.1-2ubuntu0.4no fix listed
LowUBUNTU-CVE-2026-41080expat@2.6.1-2ubuntu0.4no fix listed
LowUBUNTU-CVE-2025-11495binutils@2.42-4ubuntu2.10no fix listed
LowUBUNTU-CVE-2026-59846libssh@0.10.6-2ubuntu0.40.10.6-2ubuntu0.5
LowUBUNTU-CVE-2026-18477tar@1.35+dfsg-3ubuntu0.4no fix listed
LowUBUNTU-CVE-2025-6141ncurses@6.4+20240113-1ubuntu2.16.4+20240113-1ubuntu2.2
LowUSN-8688-1pam@1.5.3-5ubuntu5.61.5.3-5ubuntu5.7
LowUBUNTU-CVE-2026-27171zlib@1:1.3.dfsg-3.1ubuntu2.11:1.3.dfsg-3.1ubuntu2.2
LowUBUNTU-CVE-2025-66382expat@2.6.1-2ubuntu0.4no fix listed
LowUBUNTU-CVE-2026-40228systemd@255.4-1ubuntu8.17no fix listed
LowUBUNTU-CVE-2026-32778expat@2.6.1-2ubuntu0.4no fix listed
LowUBUNTU-CVE-2026-57062gnupg2@2.4.4-2ubuntu17.42.4.4-2ubuntu17.6
LowUBUNTU-CVE-2026-53910diffutils@1:3.10-1build11:3.10-1ubuntu0.1
LowUBUNTU-CVE-2025-66861binutils@2.42-4ubuntu2.10no fix listed
LowUBUNTU-CVE-2026-6368glibc@2.39-0ubuntu8.82.39-0ubuntu8.9

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.6latest2 days ago11.0.2500101281,185

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/helmforge/tomcat.svg)](https://charts.stackradar.io/charts/helmforge/tomcat)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.