StackRadar

dave Helm chart

it-at-mOfficialVerified publisher

Scored 14 Sept 2026

DAVe traffic counting plattform

Latest 0.2.15 11 days agoApp version not verified against the render 0Artifact Hub

dave 0.2.15 deploys 11 container images: ghcr.io/it-at-m/dave-admin-portal/dave-adminportal, ghcr.io/it-at-m/dave-backend/dave-backend, ghcr.io/it-at-m/dave-document-storage/dave-document-storage, ghcr.io/it-at-m/dave-eai/dave-eai and 6 more. Across the 10 measured, 1,355 findings6 critical, 4 high. The highest contribution is GHSA-f58c-gq56-vjjf in tika-parser-pdf-module 2.9.3, fixed in 3.2.2.

Radar Score

15,089642021,143

1,355 findings over 10 of 11 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

11 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal10.0.000144453
ghcr.io/it-at-m/dave-backend/dave-backend10.0.001752725
ghcr.io/it-at-m/dave-document-storage/dave-document-storage10.0.01013781,124
ghcr.io/it-at-m/dave-eai/dave-eai10.0.000737479
ghcr.io/it-at-m/dave-frontend/dave-frontend10.0.000144453
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai10.0.000642515
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal10.0.000144453
bitnamilegacy/elasticsearch9.1.2-debian-12-r031623614,681
bitnamilegacy/postgresql17.6.0-debian-12-r011522203,097
bitnami/keycloak×226.3.3-debian-12-r0unmeasured
bitnamilegacy/postgresqllatest11522213,109

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

610 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-5435glibc@2.36-9+deb12u10no fix listed
LowGHSA-c2gf-v879-257jnetty-codec-http2@4.1.118.Final4.1.135.Final
LowBIT-elasticsearch-2026-56145elasticsearch@9.1.2-08.19.18
LowBIT-elasticsearch-2026-72679elasticsearch@9.1.2-08.19.20
LowDEBIAN-CVE-2026-54369acl@2.3.1-3no fix listed
LowDEBIAN-CVE-2017-16231pcre3@2:8.39-15no fix listed
LowGHSA-5cv4-jp36-h3mwgolang.org/x/net@v0.42.00.55.0
LowBIT-elasticsearch-2025-68384elasticsearch@9.1.2-08.19.9
LowGHSA-qf7c-7r9h-mm92x-pack-security@9.1.29.1.9
LowDEBIAN-CVE-2026-7017perl@5.36.0-7+deb12u2no fix listed
LowGHSA-84h7-rjj3-6jx4netty-codec-http@4.1.118.Final4.1.129.Final
LowRHSA-2026:64800glib2@2.68.4-19.el9_8.10:2.68.4-19.el9_8.10
LowDEBIAN-CVE-2021-4214libpng1.6@1.6.39-2no fix listed
LowDEBIAN-CVE-2026-54371attr@1:2.5.1-4no fix listed
LowGHSA-3pjw-73gf-8qr5jackson-databind@2.21.22.21.4
LowRHSA-2026:58936sqlite@3.34.1-10.el9_80:3.34.1-11.el9_8
LowBIT-elasticsearch-2026-72636elasticsearch@9.1.2-08.19.20
LowRHSA-2025:22660systemd@252-55.el9_7.20:252-55.el9_7.7
LowBIT-elasticsearch-2026-72638elasticsearch@9.1.2-08.19.20
LowBIT-elasticsearch-2026-72645elasticsearch@9.1.2-08.19.20
LowBIT-elasticsearch-2026-72647elasticsearch@9.1.2-08.19.20
LowBIT-elasticsearch-2026-72684elasticsearch@9.1.2-08.19.21
LowBIT-elasticsearch-2026-72687elasticsearch@9.1.2-08.19.20
LowGHSA-4q2v-9p7v-3v22reactor-netty-http@1.0.451.2.8
LowGHSA-xmv7-r254-6q78netty-resolver-dns@4.1.118.Final4.1.135.Final
LowDEBIAN-CVE-2025-15079curl@7.88.1-10+deb12u12no fix listed
LowDSA-5979-1libxslt@1.1.35-1+deb12u11.1.35-1+deb12u2
LowRHSA-2026:0067tar@2:1.34-7.el92:1.34-9.el9_7
LowBIT-java-2026-60147java@21.0.8-12-01.8.0
LowBIT-elasticsearch-2025-37731elasticsearch@9.1.2-08.19.8
LowDEBIAN-CVE-2026-6429curl@7.88.1-10+deb12u12no fix listed
LowRHSA-2026:50147libgcrypt@1.10.0-11.el90:1.10.0-13.el9_8
LowDEBIAN-CVE-2024-22365pam@1.5.2-6+deb12u11.5.2-6+deb12u2
LowGHSA-c69g-56f8-xwqjnetty-codec-http2@4.1.135.Final4.1.136.Final
LowDEBIAN-CVE-2026-22796openssl@3.0.17-1~deb12u23.0.18-1~deb12u2
LowGHSA-2474-2566-3qxpbatik-script@1.141.17
LowDEBIAN-CVE-2025-10148curl@7.88.1-10+deb12u127.88.1-10+deb12u15
LowRHSA-2026:61247libxml2@2.9.13-14.el9_8.10:2.9.13-14.el9_8.4
LowDEBIAN-CVE-2026-22695libpng1.6@1.6.39-21.6.39-2+deb12u2
LowGHSA-hjcp-jmpx-g3qmhttpclient5@5.5.25.6.3
LowDEBIAN-CVE-2026-1965curl@7.88.1-10+deb12u12no fix listed
LowDEBIAN-CVE-2022-0563util-linux@2.38.1-5+deb12u3no fix listed
LowDEBIAN-CVE-2025-3576krb5@1.20.1-2+deb12u31.20.1-2+deb12u4
LowDEBIAN-CVE-2026-4878libcap2@1:2.66-4+deb12u11:2.66-4+deb12u3
LowDEBIAN-CVE-2026-11979libxml2@2.9.14+dfsg-1.3~deb12u2no fix listed
LowRHSA-2026:0719gnupg2@2.3.3-4.el90:2.3.3-5.el9_7
LowDEBIAN-CVE-2026-7168curl@7.88.1-10+deb12u127.88.1-10+deb12u15
LowBIT-postgresql-2025-12818postgresql@17.6.0-013.23.0
LowDEBIAN-CVE-2026-86140libxml2@2.9.14+dfsg-1.3~deb12u2no fix listed
LowBIT-elasticsearch-2026-78607elasticsearch@9.1.2-08.19.19

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.2.15latest11 days ago642021,14315,089

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/it-at-m/dave.svg)](https://charts.stackradar.io/charts/it-at-m/dave)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.