StackRadar

openrefine Helm chart

inseefrlab

Scored 14 Sept 2026

OpenRefine (previously Google Refine) is a powerful tool for working with messy data, cleaning it; transforming it from one format into another; and extending it with web services and external data.

Latest 3.5.0 3 years agodeploys tag 3.7.0 0Artifact Hub

openrefine 3.5.0 deploys 1 container image: easypi/openrefine. Across them, 113 findings1 critical, 4 high 2 on CISA KEV. The highest contribution is GHSA-vv7r-c36w-3prj in commons-fileupload 1.4, fixed in 1.6.0.

Radar Score

1,754143177

113 findings over 1 of 1 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
easypi/openrefine3.7.01431771,754

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

113 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-q4rv-gq96-w7c5jetty-server@9.4.48.v202206229.4.57.v20241219
LowGHSA-vc5p-v9hr-52mjlog4j-core@2.19.02.25.3
LowDSA-5200-1libtirpc@1.3.1-11.3.1-1+deb11u1
LowDSA-5174-1gnupg2@2.2.27-2+deb11u12.2.27-2+deb11u2
LowGHSA-h383-gmxw-35v2log4j-1.2-api@2.19.02.25.4
LowGHSA-hmr7-m48g-48f6jetty-http@9.4.48.v202206229.4.52
LowGHSA-4265-ccf5-phj5commons-compress@1.221.26.0
LowDSA-5650-1util-linux@2.36.1-8+deb11u12.36.1-8+deb11u2
LowGHSA-j26w-f9rq-mr2qjetty-servlets@9.4.48.v202206229.4.54
LowDSA-5203-1gnutls28@3.7.1-53.7.1-5+deb11u2
LowDSA-5726-1krb5@1.18.3-6+deb11u11.18.3-6+deb11u5
LowDSA-5365-1curl@7.74.0-1.3+deb11u57.74.0-1.3+deb11u7
LowDSA-5587-1curl@7.74.0-1.3+deb11u57.74.0-1.3+deb11u11
LowGHSA-6hg6-v5c8-fphqlog4j-core@2.19.02.25.4
LowDLA-4321-1openssl@1.1.1n-0+deb11u11.1.1w-0+deb11u4
LowDLA-3926-1perl@5.32.1-4+deb11u25.32.1-4+deb11u4
LowGHSA-4g9r-vxhx-9pgxcommons-compress@1.221.26.0
LowDSA-5349-1gnutls28@3.7.1-53.7.1-5+deb11u3
LowDLA-4432-1curl@7.74.0-1.3+deb11u57.74.0-1.3+deb11u16
LowDLA-3910-1e2fsprogs@1.46.2-21.46.2-2+deb11u1
LowDSA-5678-1glibc@2.31-13+deb11u32.31-13+deb11u10
LowDLA-4267-1gnutls28@3.7.1-53.7.1-5+deb11u8
LowDLA-4063-1gnutls28@3.7.1-53.7.1-5+deb11u7
LowGHSA-cgwf-w82q-5jrrcommons-compress@1.221.24.0
LowGHSA-hjcp-jmpx-g3qmhttpclient5@5.2.15.6.3
LowDLA-4061-1libtasn1-6@4.16.0-24.16.0-2+deb11u2
LowGHSA-xvr9-35cr-46v9mariadb-java-client@3.0.83.3.5
LowGHSA-r7wm-3cxj-wff9jackson-core@2.13.42.18.8
LowDLA-4490-1openssl@1.1.1n-0+deb11u11.1.1w-0+deb11u5
LowGHSA-hgj6-7826-r7m5jackson-databind@2.13.42.18.8
LowGHSA-5jmj-h7xm-6q6vjackson-databind@2.13.42.18.9
LowGHSA-562r-vg33-8x8hpostgresql@42.5.042.5.1
LowDLA-4259-1systemd@247.3-7247.3-7+deb11u7
LowGHSA-qh8g-58pp-2wxhjetty-http@9.4.48.v2022062212.0.12
LowDLA-3951-1curl@7.74.0-1.3+deb11u57.74.0-1.3+deb11u14
LowDLA-3875-1gnutls28@3.7.1-53.7.1-5+deb11u6
LowGHSA-7p3p-8qv8-m2vhjetty-server@9.4.48.v20220622no fix listed
LowGHSA-g9jj-cgmh-9f38mariadb-java-client@3.0.83.3.5
LowGHSA-3gh6-v5v9-6v9jjetty-servlets@9.4.48.v202206229.4.52
LowDLA-4492-1gnutls28@3.7.1-53.7.1-5+deb11u9
LowGHSA-7g45-4rm6-3mm3guava@31.0.1-jre32.0.0-android
LowGHSA-qxvw-fvwx-5cp7mariadb-java-client@3.0.83.3.5
LowDLA-4176-1openssl@1.1.1n-0+deb11u11.1.1w-0+deb11u3
LowDLA-3930-1libsepol@3.1-13.1-1+deb11u1
LowDLA-4181-1glibc@2.31-13+deb11u32.31-13+deb11u13
LowGHSA-5mg8-w23w-74h3guava@31.0.1-jre32.0.0-android
LowDLA-4065-1krb5@1.18.3-6+deb11u11.18.3-6+deb11u6
LowDLA-4306-1pam@1.4.0-9+deb11u11.4.0-9+deb11u2
LowDLA-4130-1shadow@1:4.8.1-11:4.8.1-1+deb11u1
LowDLA-4143-1glibc@2.31-13+deb11u32.31-13+deb11u12

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.5.0latest3 years ago3.7.01431771,754

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/inseefrlab/openrefine.svg)](https://charts.stackradar.io/charts/inseefrlab/openrefine)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.