StackRadar

erpnext Helm chart

improwisedVerified publisher

Scored 14 Sept 2026

Kubernetes Helm Chart for the lastest stable ERPNext branch

Latest 3.3.0 3 years agoapp version v13.4.1 0Artifact Hub

erpnext 3.3.0 deploys 3 container images: bitnami/redis, improwised/erpnext-worker and frappe/frappe-socketio. Across the 2 measured, 441 findings2 critical, 6 high 3 on CISA KEV. The highest contribution is GHSA-j7hp-h8jx-5ppr in pillow 8.2.0, fixed in 10.0.1.

Radar Score

6,50126134298

441 findings over 2 of 3 images measured

KEV ×3 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
bitnami/redis×35.0.10-debian-10-r105unmeasured
improwised/erpnext-worker×5v13.4.1251042245,030
frappe/frappe-socketiov13.4.10130741,471

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

115 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumGHSA-qq89-hq3f-393ptar@6.1.06.1.9
MediumGHSA-p5w8-wqhj-9hhfsqlparse@0.4.10.4.2
MediumGHSA-3f63-hfp8-52jqpillow@8.2.010.2.0
MediumGHSA-qw25-v68c-qjf3django@1.11.294.2.26
MediumGHSA-v3c5-jqr6-7qm8future@0.18.20.18.3
MediumGHSA-f8q6-p94x-37v3minimatch@3.0.43.0.5
MediumDLA-3559-1libssh2@1.8.0-2.11.8.0-2.1+deb10u1
MediumDLA-3477-1python3.7@3.7.3-2+deb10u33.7.3-2+deb10u5
MediumGHSA-pw3c-h7wp-cvhxpillow@8.2.09.0.0
MediumGHSA-72xf-g2v4-qvf3tough-cookie@2.5.04.1.3
MediumGHSA-5955-9wpr-37jhtar@6.1.06.1.9
MediumGHSA-rc47-6667-2j5jhttp-cache-semantics@4.1.04.1.1
MediumGHSA-j8r2-6x86-q33qrequests@2.25.12.31.0
MediumDSA-4944-1krb5@1.17-3+deb10u11.17-3+deb10u2
MediumPYSEC-2026-3952gitpython@3.1.173.1.54
MediumGHSA-v9hf-5j83-6xpppymysql@1.0.21.1.1
MediumPYSEC-2023-192urllib3@1.26.52.0.6
MediumGHSA-956x-8gvw-wg5vgitpython@3.1.173.1.51
MediumGHSA-xg9f-g7g7-2323werkzeug@0.16.12.2.3
MediumPYSEC-2024-60idna@2.103.7
MediumGHSA-3h5v-q93c-6h6qws@7.4.67.5.10
MediumGHSA-8x94-hmjh-97hqdjango@1.11.293.2.15
MediumDSA-4942-1systemd@241-7~deb10u7241-7~deb10u8
MediumGHSA-ffqj-6fqr-9h24pyjwt@1.7.12.4.0
MediumGHSA-r7qp-cfhv-p84wengine.io@3.5.03.6.1
MediumPYSEC-2026-2161gitpython@3.1.173.1.47
MediumGHSA-9v9h-cgj8-h64pcryptography@3.4.742.0.2
MediumGHSA-m2vv-5vj5-2hm7pillow@8.2.09.2.0
MediumGHSA-xrcv-f9gm-v42cpillow@8.2.09.0.0
MediumPYSEC-2022-203werkzeug@0.16.12.1.1
MediumGHSA-8gq9-2x98-w8hfprotobuf@3.17.33.18.3
MediumGHSA-wqc8-x2pr-7jqhrestrictedpython@5.15.3
MediumGHSA-2xpw-w6gg-jr37urllib3@1.26.52.6.0
MediumGHSA-gm62-xv2j-4w53urllib3@1.26.52.6.0
MediumGHSA-8ghj-p4vj-mr35pillow@8.2.010.0.0
MediumGHSA-3ww4-gg4f-jr7fcryptography@3.4.742.0.0
MediumGHSA-v342-4xr9-x3q3frappe@13.4.114.91.0
MediumPYSEC-2023-221werkzeug@0.16.12.3.8
MediumGHSA-r9mr-m37c-5fr3gitpython@3.1.173.1.54
MediumPYSEC-2024-230certifi@2021.5.302024.7.4
MediumGHSA-4xqq-73wg-5mjpgit-url-parse@1.2.2no fix listed
MediumDLA-3530-1openssl@1.1.1d-0+deb10u61.1.1n-0+deb10u6
MediumPYSEC-2023-254cryptography@3.4.741.0.6
MediumPYSEC-2026-3717django@1.11.295.2.17
MediumGHSA-cqmj-92xf-r6r9socket.io-parser@3.4.13.4.3
MediumDLA-3213-1krb5@1.17-3+deb10u11.17-3+deb10u5
MediumGHSA-284h-m62q-gf8wgitpython@3.1.173.1.59
MediumDLA-3613-1curl@7.64.0-4+deb10u27.64.0-4+deb10u7
MediumGHSA-37ch-88jc-xwx2path-to-regexp@0.1.70.1.13
MediumGHSA-9wv6-86v2-598jpath-to-regexp@0.1.70.1.10

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.3.0latest3 years agov13.4.1261342986,501

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/improwised/erpnext.svg)](https://charts.stackradar.io/charts/improwised/erpnext)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.