StackRadar

label-studio Helm chart

inseefrlab

Scored 14 Sept 2026

Data Science starts with data. Label Studio removes the pain of labeling it.

Latest 2.3.1 3 years agodeploys tag latest 0Artifact Hub

label-studio 2.3.1 deploys 3 container images: library/alpine, heartexlabs/label-studio and bitnami/postgresql. Across the 2 measured, 258 findings1 critical, 3 high. The highest contribution is ALPINE-CVE-2026-42945 in nginx 1.28.2-r1, fixed in 1.28.3-r1.

Radar Score

3,1571346207

258 findings over 2 of 3 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
library/alpinelatest0046149
heartexlabs/label-studiolatest13422013,008
bitnami/postgresql12unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

248 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2026-3805curl@8.17.0-r18.19.0-r0
LowALPINE-CVE-2026-14456openssl@3.5.5-r03.5.8-r0
LowPYSEC-2026-2237nltk@3.9.33.9.4
LowGHSA-386q-5hp3-95m9datamodel-code-generator@0.26.10.60.2
LowGHSA-p3m8-78j2-g5p3nltk@3.9.33.10.0
LowALPINE-CVE-2026-9076openssl@3.5.5-r03.5.7-r0
LowGHSA-62p4-gmf7-7g93pillow@12.1.112.3.0
LowALPINE-CVE-2026-82209curl@8.17.0-r18.22.0-r0
LowALPINE-CVE-2026-80255curl@8.17.0-r18.22.0-r0
LowGHSA-mf9v-mfxr-j63jurllib3@2.6.32.7.0
LowGHSA-whj4-6x5x-4v2jpillow@12.1.112.2.0
LowGHSA-rgxp-2hwp-jwggpyarrow@22.0.023.0.1
LowPYSEC-2026-3452pillow@12.1.112.3.0
LowALPINE-CVE-2026-11564curl@8.17.0-r18.22.0-r0
LowGHSA-p4gq-832x-fm9vnltk@3.9.33.10.0
LowALPINE-CVE-2026-6732libxml2@2.13.9-r02.13.9-r1
LowGHSA-3936-cmfr-pm3mblack@24.8.026.3.1
LowALPINE-CVE-2026-13608curl@8.17.0-r18.22.0-r0
LowALPINE-CVE-2026-5773curl@8.17.0-r18.20.0-r0
LowGHSA-vjc4-5qp5-m44jpillow@12.1.112.3.0
LowALPINE-CVE-2026-63072openssl@3.5.5-r03.5.8-r0
LowALPINE-CVE-2026-56434nginx@1.28.2-r11.28.3-r6
LowALPINE-CVE-2026-11586curl@8.17.0-r18.22.0-r0
LowALPINE-CVE-2026-45445openssl@3.5.5-r03.5.7-r0
LowGHSA-xj96-63gp-2gmrpillow@12.1.112.3.0
LowGHSA-rhp5-r9x4-f5g2nltk@3.9.33.10.0
LowPYSEC-2026-3724nltk@3.9.33.9.4
LowPYSEC-2026-3738nltk@3.9.33.10.3
LowALPINE-CVE-2026-80230curl@8.17.0-r18.22.0-r0
LowALPINE-CVE-2026-76641expat@2.7.4-r02.8.4-r0
LowALPINE-CVE-2026-31789openssl@3.5.5-r03.5.6-r0
LowALPINE-CVE-2026-54874openssl@3.5.5-r03.5.8-r0
LowALPINE-CVE-2026-42766openssl@3.5.5-r03.5.7-r0
LowGHSA-qx2g-xrx7-vfh8nltk@3.9.33.10.1
LowALPINE-CVE-2026-63075openssl@3.5.5-r03.5.8-r0
LowGHSA-wgvc-ghv9-3pmmujson@5.8.05.12.0
LowALPINE-CVE-2026-22184zlib@1.3.1-r21.3.2-r0
LowGHSA-c8rr-9gxc-jprvujson@5.8.05.12.0
LowALPINE-CVE-2026-45186expat@2.7.4-r02.8.1-r0
LowGHSA-97qj-x29f-37w7nltk@3.9.33.10.3
LowALPINE-CVE-2026-33630c-ares@1.34.6-r01.34.8-r0
LowALPINE-CVE-2026-42934nginx@1.28.2-r11.28.3-r1
LowGHSA-8359-h9fx-j6v9datamodel-code-generator@0.26.10.62.0
LowALPINE-CVE-2026-82208curl@8.17.0-r18.22.0-r0
LowGHSA-45hq-cxwh-f6vcpillow@12.1.112.3.0
LowGHSA-c38f-wx89-p2xgujson@5.8.05.12.1
LowGHSA-5x94-69rx-g8h2pillow@12.1.112.3.0
LowGHSA-phj9-mv4w-65pmpillow@12.1.112.3.0
LowGHSA-5578-w22f-pfx9datamodel-code-generator@0.26.10.64.0
LowGHSA-f2ff-p2ww-7p4psqlparse@0.5.50.6.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.3.1latest3 years agolatest13462073,157

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/inseefrlab/label-studio.svg)](https://charts.stackradar.io/charts/inseefrlab/label-studio)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.