StackRadar

superset Helm chart

inseefrlab

Scored 14 Sept 2026

Apache Superset is a modern data exploration and visualization platform.

Latest 1.4.0 3 years agodeploys tag 9cdaa280429ec297db16d56c94fd77b5d2aff107 1Artifact Hub

superset 1.4.0 deploys 4 container images: jwilder/dockerize, apache/superset, bitnami/postgresql and bitnami/redis. Across the 2 measured, 517 findings3 critical, 12 high 8 on CISA KEV. The highest contribution is GHSA-5cx2-vq3h-x52c in apache-superset 0.0.0.dev0, fixed in 2.1.0.

Radar Score

7,129312129372

517 findings over 2 of 4 images measured

KEV ×8 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

4 images
ImageTagVulnerabilitiesRadar Score
jwilder/dockerize×3latest00554502
apache/superset×39cdaa280429ec297db16d56c94fd77b5d2aff1073121243186,627
bitnami/postgresql14.2.0-debian-10-r70unmeasured
bitnami/redis6.2.6-debian-10-r120unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

517 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDSA-5122-1gzip@1.10-41.10-4+deb11u1
LowDSA-5123-1xz-utils@5.2.5-25.2.5-2.1~deb11u1
LowGHSA-89gr-r52h-f8rxgolang.org/x/crypto@v0.45.00.52.0
LowGHSA-3hp7-4qq4-v5c6apache-superset@0.0.0.dev03.0.0
LowDEBIAN-CVE-2022-24051mariadb-10.5@1:10.5.12-0+deb11u11:10.5.15-0+deb11u1
LowGHSA-jppx-rxg9-jmrxgolang.org/x/crypto@v0.45.00.52.0
LowDEBIAN-CVE-2022-24050mariadb-10.5@1:10.5.12-0+deb11u11:10.5.15-0+deb11u1
LowGHSA-hxwh-jpp2-84pmflask-cors@3.0.104.0.2
LowGHSA-44wm-f244-xhp3pillow@9.1.010.3.0
LowGHSA-62p4-gmf7-7g93pillow@9.1.012.3.0
LowPYSEC-2026-2098aiohttp@3.7.43.13.4
LowGHSA-p998-jp59-783maiohttp@3.7.43.13.4
LowGHSA-8qpw-xqxj-h4r2aiohttp@3.7.43.9.2
LowDLA-3954-1postgresql-13@13.7-0+deb11u113.17-0+deb11u1
LowDLA-4297-1imagemagick@8:6.9.11.60+dfsg-1.38:6.9.11.60+dfsg-1.3+deb11u6
LowDSA-5330-1curl@7.74.0-1.3+deb11u17.74.0-1.3+deb11u5
LowDSA-5554-1postgresql-13@13.7-0+deb11u113.13-0+deb11u1
LowGHSA-9hcr-9hcv-x6pvflask-appbuilder@4.0.04.3.0
LowGHSA-fxjg-28fm-pfxhapache-superset@0.0.0.dev02.1.0
LowGHSA-6jhg-hg63-jvvfaiohttp@3.7.43.13.3
LowGHSA-g3cq-j2xw-wf74aiohttp@3.7.43.14.1
LowGHSA-f8vc-f28w-x9c9apache-superset@0.0.0.dev01.2.0
LowGHSA-g84x-mcqj-x9qqaiohttp@3.7.43.13.3
LowGHSA-vjc4-5qp5-m44jpillow@9.1.012.3.0
LowGHSA-8w7f-8pr9-xgwjapache-superset@0.0.0.dev04.1.2
LowGHSA-8wv5-x4w7-5gwwthrift@0.13.00.24.0
LowGHSA-jj3x-wxrx-4x23aiohttp@3.7.43.13.3
LowDLA-3907-1sqlite3@3.34.1-33.34.1-3+deb11u1
LowGHSA-q2x7-8rv6-6q7hjinja2@3.0.33.1.5
LowGHSA-6pjx-3pjc-mrj8thrift@0.13.00.24.0
LowGHSA-xj96-63gp-2gmrpillow@9.1.012.3.0
LowGHSA-6mq8-rvhq-8wggaiohttp@3.7.43.13.3
LowDSA-5142-1libxml2@2.9.10+dfsg-6.72.9.10+dfsg-6.7+deb11u2
LowGHSA-xqr8-7jwr-rhp7certifi@2021.10.82023.7.22
LowGHSA-5wmx-573v-2qwqmarkdown@3.3.43.8.1
LowGHSA-fpfv-jqm9-f5jmnumpy@1.21.11.22
LowPYSEC-2023-247aiohttp@3.7.43.8.0
LowGHSA-952p-6rrq-rcjvmicromatch@4.0.44.0.8
LowGHSA-63hw-fmq6-xxg2aiohttp@3.7.43.14.1
LowGHSA-2qfp-q593-8484brotli@1.0.91.2.0
LowGHSA-gmj6-6f8f-6699jinja2@3.0.33.1.5
LowDSA-5147-1dpkg@1.20.91.20.10
LowPYSEC-2026-777apache-superset@0.0.0.dev01.5.3
LowGHSA-6v7p-g79w-8964msgpack@1.0.21.2.1
LowGHSA-xcgm-r5h9-7989aiohttp@3.7.43.14.1
LowGHSA-q4h4-gmj2-qvw2golang.org/x/crypto@v0.45.00.52.0
LowGHSA-45c4-8wx5-qw6waiohttp@3.7.43.8.5
LowPYSEC-2026-782apache-superset@0.0.0.dev01.5.3
LowGHSA-w879-237q-wc7rgolang.org/x/crypto@v0.45.00.52.0
LowPYSEC-2026-779apache-superset@0.0.0.dev01.5.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.4.0latest3 years ago9cdaa280429ec297db16d56c94fd77b5d2aff1073121293727,129

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/inseefrlab/superset.svg)](https://charts.stackradar.io/charts/inseefrlab/superset)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.