StackRadar

superset 1.4.0 Helm chart

inseefrlab

Scored 14 Sept 2026

Apache Superset is a modern data exploration and visualization platform.

Version 1.4.0 3 years agodeploys tag 9cdaa280429ec297db16d56c94fd77b5d2aff107 1Artifact Hub

superset 1.4.0 deploys 4 container images: jwilder/dockerize, apache/superset, bitnami/postgresql and bitnami/redis. Across the 2 measured, 517 findings3 critical, 12 high 8 on CISA KEV. The highest contribution is GHSA-5cx2-vq3h-x52c in apache-superset 0.0.0.dev0, fixed in 2.1.0.

Radar Score

7,129312129372

517 findings over 2 of 4 images measured

KEV ×8 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

4 images
ImageTagVulnerabilitiesRadar Score
jwilder/dockerize×3latest00554502
apache/superset×39cdaa280429ec297db16d56c94fd77b5d2aff1073121243186,627
bitnami/postgresql14.2.0-debian-10-r70unmeasured
bitnami/redis6.2.6-debian-10-r120unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

372 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-xcgm-r5h9-7989aiohttp@3.7.43.14.1
LowGHSA-q4h4-gmj2-qvw2golang.org/x/crypto@v0.45.00.52.0
LowGHSA-45c4-8wx5-qw6waiohttp@3.7.43.8.5
LowPYSEC-2026-782apache-superset@0.0.0.dev01.5.3
LowGHSA-w879-237q-wc7rgolang.org/x/crypto@v0.45.00.52.0
LowPYSEC-2026-779apache-superset@0.0.0.dev01.5.3
LowGHSA-f9vj-2wh5-fj8jwerkzeug@2.0.33.0.6
LowGHSA-r6ph-v2qm-q3c2cryptography@3.4.746.0.5
LowPYSEC-2026-780apache-superset@0.0.0.dev01.5.3
LowPYSEC-2026-2095aiohttp@3.7.43.13.4
LowPYSEC-2026-778apache-superset@0.0.0.dev01.5.3
LowGHSA-4fvr-rgm6-gqmcaiohttp@3.7.43.14.1
LowGHSA-9832-mgg4-3gr6apache-superset@0.0.0.dev0no fix listed
LowDSA-5200-1libtirpc@1.3.1-11.3.1-1+deb11u1
LowGHSA-45hq-cxwh-f6vcpillow@9.1.012.3.0
LowDSA-5174-1gnupg2@2.2.27-22.2.27-2+deb11u2
LowDSA-5628-1imagemagick@8:6.9.11.60+dfsg-1.38:6.9.11.60+dfsg-1.3+deb11u3
LowGHSA-5x94-69rx-g8h2pillow@9.1.012.3.0
LowGHSA-phj9-mv4w-65pmpillow@9.1.012.3.0
LowGHSA-f2ff-p2ww-7p4psqlparse@0.3.00.6.0
LowGHSA-pwgv-4x5q-6m9fsqlparse@0.3.00.6.0
LowGHSA-8v84-f9pq-wr9xpillow@9.1.012.3.0
LowGHSA-43fp-rhv2-5gv8certifi@2021.10.82022.12.07
LowDLA-3878-1libxml2@2.9.10+dfsg-6.72.9.10+dfsg-6.7+deb11u5
LowPYSEC-2026-3553cryptography@3.4.749.0.0
LowGHSA-wf93-45jw-7689pip@21.2.426.1.2
LowGHSA-rrm6-wvj7-cwh2sqlparse@0.3.00.4.4
LowGHSA-6r8x-57c9-28j4pillow@9.1.012.3.0
LowGHSA-9hw9-ch79-4vh6pillow@9.1.012.3.0
LowGHSA-jjj6-mw9f-p565pillow@9.1.012.3.0
LowGHSA-xgmm-8j9v-c9wxpyjwt@2.2.02.13.0
LowPYSEC-2026-781apache-superset@0.0.0.dev01.5.3
LowDSA-5266-1expat@2.2.10-2+deb11u22.2.10-2+deb11u5
LowGHSA-3m2g-v7jf-7fxcapache-superset@0.0.0.dev06.0.0
LowDSA-5202-1unzip@6.0-266.0-26+deb11u1
LowGHSA-h75v-3vvj-5mfjjinja2@3.0.33.1.4
LowGHSA-v92g-xgxw-vvmmmako@1.1.41.3.11
LowGHSA-7gpw-8wmc-pm8gaiohttp@3.7.43.9.4
LowDSA-5484-1librsvg@2.50.3+dfsg-12.50.3+dfsg-1+deb11u1
LowPYSEC-2024-161pyarrow@5.0.017.0.0
LowDLA-4251-1libxml2@2.9.10+dfsg-6.72.9.10+dfsg-6.7+deb11u8
LowDLA-3879-1bluez@5.55-3.15.55-3.1+deb11u2
LowGHSA-9hjg-9r4m-mvj7requests@2.26.02.32.4
LowGHSA-w2fm-2cpv-w7v5aiohttp@3.7.43.13.4
LowDSA-5650-1util-linux@2.36.1-8+deb11u12.36.1-8+deb11u2
LowDSA-5490-1aom@1.0.0.errata1-31.0.0.errata1-3+deb11u1
LowDSA-5236-1expat@2.2.10-2+deb11u22.2.10-2+deb11u4
LowGHSA-qvrw-v9rv-5rjxaiohttp@3.7.43.9.0
LowGHSA-8495-4g3g-x7praiohttp@3.7.43.10.11
LowGHSA-h5c8-rqwp-cp95jinja2@3.0.33.1.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.4.0latest3 years ago9cdaa280429ec297db16d56c94fd77b5d2aff1073121293727,129

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/inseefrlab/superset.svg)](https://charts.stackradar.io/charts/inseefrlab/superset)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.