StackRadar

image-storage-service 0.5.1 Helm chart

jtektVerified publisher

Scored 25 Sept 2026

Helm chart for the Image Storage Service

Version 0.5.1 2 days agoapp version v1.16.17 0Artifact Hub

image-storage-service 0.5.1 deploys 4 container images: library/kong, bitnamilegacy/mongodb, public.ecr.aws/jtekt-corporation/image-storage-service and public.ecr.aws/jtekt-corporation/image-storage-service-gui. Across them, 2,042 findings — 11 critical, 13 high — 10 on CISA KEV. The highest contribution is DEBIAN-CVE-2025-27363 in freetype 2.12.1+dfsg-5+deb12u3, fixed in 2.12.1+dfsg-5+deb12u4.

Radar Score

23,75211133931,622

2,042 findings over 4 of 4 images measured

KEV ×10 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

4 images
ImageTagVulnerabilitiesRadar Score
library/kong×23.622512032,984
bitnamilegacy/mongodb6.0.10-debian-11-r825231852,474
public.ecr.aws/jtekt-corporation/image-storage-servicev1.16.174522688513,016
public.ecr.aws/jtekt-corporation/image-storage-service-guiv1.9.431933495,278

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

1,102 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-6845binutils@2.40-2no fix listed
LowDEBIAN-CVE-2026-73282openssh@1:9.2p1-2+deb12u3no fix listed
LowUBUNTU-CVE-2025-4877libssh@0.9.6-2ubuntu0.22.04.30.9.6-2ubuntu0.22.04.4
LowDEBIAN-CVE-2026-3949libheif@1.15.1-1no fix listed
LowDEBIAN-CVE-2026-6192openjpeg2@2.5.0-22.5.0-2+deb12u3
LowDEBIAN-CVE-2013-0337nginx@1.27.2-1~bookwormno fix listed
LowDEBIAN-CVE-2026-6469postgresql-15@15.8-0+deb12u115.19-0+deb12u1
LowDEBIAN-CVE-2025-1149binutils@2.40-2no fix listed
LowDEBIAN-CVE-2026-16742systemd@252.30-1~deb12u2no fix listed
LowGHSA-v6h2-p8h4-qcjwbrace-expansion@2.0.12.0.2
LowDEBIAN-CVE-2008-3134imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2no fix listed
LowDEBIAN-CVE-2025-61145tiff@4.5.0-6+deb12u1no fix listed
LowDEBIAN-CVE-2026-18374glibc@2.36-9+deb12u8no fix listed
LowUBUNTU-CVE-2026-53613util-linux@2.37.2-4ubuntu3.42.37.2-4ubuntu3.6
LowUBUNTU-CVE-2026-53615util-linux@2.37.2-4ubuntu3.42.37.2-4ubuntu3.6
LowUBUNTU-CVE-2026-91187dash@0.5.11+git20210903+057cd650a4ed-3build1no fix listed
LowDEBIAN-CVE-2026-56363imagemagick@8:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u12
LowDEBIAN-CVE-2026-62363imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2no fix listed
LowDEBIAN-CVE-2026-93587imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2no fix listed
LowGO-2026-4403stdlib@go1.19.121.23.9
LowDEBIAN-CVE-2026-81893gdk-pixbuf@2.42.10+dfsg-1+deb12u1no fix listed
LowDEBIAN-CVE-2025-69644binutils@2.40-2no fix listed
LowDEBIAN-CVE-2026-14678postgresql-15@15.8-0+deb12u115.19-0+deb12u1
LowDEBIAN-CVE-2026-18024postgresql-15@15.8-0+deb12u115.19-0+deb12u1
LowDEBIAN-CVE-2026-27799imagemagick@8:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u7
LowDEBIAN-CVE-2023-29383shadow@1:4.13+dfsg1-1+b11:4.13+dfsg1-1+deb12u1
LowDEBIAN-CVE-2026-56131expat@2.5.0-1+deb12u12.5.0-1+deb12u3
LowDEBIAN-CVE-2026-41991gzip@1.12-1no fix listed
LowDEBIAN-CVE-2025-15224curl@7.88.1-10+deb12u7no fix listed
LowDEBIAN-CVE-2025-9820gnutls28@3.7.9-2+deb12u33.7.9-2+deb12u6
LowDEBIAN-CVE-2023-6228tiff@4.5.0-6+deb12u1no fix listed
LowDEBIAN-CVE-2026-22185openldap@2.5.13+dfsg-5no fix listed
LowGO-2026-5027golang.org/x/net@v0.14.00.55.0
LowGO-2026-5029golang.org/x/net@v0.14.00.55.0
LowGO-2026-5030golang.org/x/net@v0.14.00.55.0
LowDEBIAN-CVE-2026-4519python3.11@3.11.2-6+deb12u33.11.2-6+deb12u8
LowDEBIAN-CVE-2026-34757libpng1.6@1.6.39-21.6.39-2+deb12u5
LowGHSA-xhjh-pmcv-23jwaxios@0.21.40.31.1
LowDEBIAN-CVE-2025-61984openssh@1:9.2p1-2+deb12u31:9.2p1-2+deb12u8
LowUBUNTU-CVE-2026-0968libssh@0.9.6-2ubuntu0.22.04.30.9.6-2ubuntu0.22.04.6
LowDEBIAN-CVE-2026-42770openssl@3.0.14-1~deb12u23.0.20-1~deb12u2
LowGHSA-75v8-2h7p-7m2mformidable@2.1.22.1.3
LowDEBIAN-CVE-2026-14666postgresql-15@15.8-0+deb12u115.19-0+deb12u1
LowGHSA-78xj-cgh5-2h22ip@2.0.02.0.1
LowDEBIAN-CVE-2026-48733imagemagick@8:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u11
LowDEBIAN-CVE-2026-55595imagemagick@8:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u12
LowDEBIAN-CVE-2026-62343imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2no fix listed
LowDEBIAN-CVE-2026-33536imagemagick@8:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u8
LowDEBIAN-CVE-2026-62946imagemagick@8:6.9.11.60+dfsg-1.6+deb12u2no fix listed
LowDEBIAN-CVE-2026-18508tar@1.34+dfsg-1.2+deb12u1no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.5.1latest2 days agov1.16.1711133931,62223,752
0.4.36 months agov1.16.1711133931,62223,752

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/jtekt/image-storage-service.svg)](https://charts.stackradar.io/charts/jtekt/image-storage-service)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 24 Sept 2026 · scanned 25 Sept 2026 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.