StackRadar

ghost 4.1.0 Helm chart

k8s-home-lab-repo

Scored 14 Sept 2026

Ghost is a blogging and publishing software

Version 4.1.0 3 months agoapp version 6.41.1 0Artifact Hub

ghost 4.1.0 deploys 1 container image: library/ghost. Across them, 314 findings0 critical, 2 high. The highest contribution is GHSA-r5fr-rjxr-66jc in lodash.template 4.5.0, fixed in 4.18.0. Chart.yaml declares kubeVersion >=1.19.0-0; rendered for Kubernetes 1.19.0.

Radar Score

3,0920230282

314 findings over 1 of 1 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
library/ghost6.41.102302823,092

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

282 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-54369acl@2.3.1-3no fix listed
LowGHSA-mmx7-hfxf-jppxaxios@1.16.01.18.0
LowDEBIAN-CVE-2026-7017perl@5.36.0-7+deb12u3no fix listed
LowGHSA-xj6q-8x83-jv6gaxios@1.16.01.18.0
LowDEBIAN-CVE-2026-54371attr@1:2.5.1-4no fix listed
LowGHSA-p4xf-rf54-rj3xpnpm@10.33.010.34.0
LowGHSA-r47g-fvhr-h676dompurify@3.4.13.4.6
LowGHSA-jxxr-4gwj-5jf2brace-expansion@5.0.55.0.6
LowGHSA-gj8w-mvpf-x27xpnpm@10.33.010.34.2
LowGHSA-52v5-jr5w-gjxrsigstore@3.1.04.1.1
LowGHSA-pr7r-676h-xcf6undici@7.25.07.28.0
LowGHSA-5wx6-mg75-v57rpnpm@10.33.010.34.2
LowGHSA-gvwx-54wh-qm9jtar@7.5.137.5.17
LowGHSA-9965-vmph-33xxvalidator@7.2.013.15.20
LowGHSA-hg3w-7f8c-63hppnpm@10.33.010.33.4
LowDEBIAN-CVE-2022-0563util-linux@2.38.1-5+deb12u3no fix listed
LowGHSA-rgj7-g3m4-5g8csharp@0.34.50.35.4
LowGHSA-v2v4-37r5-5v8gip-address@10.1.010.1.1
LowGHSA-28wg-ghj8-5hjvnanoid@3.3.113.3.16
LowDEBIAN-CVE-2026-34743xz-utils@5.4.1-15.4.1-1+deb12u1
LowDEBIAN-CVE-2026-5704tar@1.34+dfsg-1.2+deb12u1no fix listed
LowGHSA-jxwj-j7wr-gfrwsanitize-html@2.17.42.17.6
LowGHSA-2v37-7h3g-55p8nanoid@3.3.113.3.18
LowDEBIAN-CVE-2026-3184util-linux@2.38.1-5+deb12u3no fix listed
LowGHSA-58qx-3vcg-4xpxws@8.20.08.20.1
LowGHSA-jr45-8vmc-qm54undici@7.25.07.29.0
LowDEBIAN-CVE-2026-7010perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2026-19487perl@5.36.0-7+deb12u3no fix listed
LowGHSA-3v7f-55p6-f55ppicomatch@4.0.34.0.4
LowDEBIAN-CVE-2026-89158pcre2@10.42-110.42-1+deb12u1
LowGHSA-7q8q-rj6j-mhjqaxios@1.16.01.18.0
LowDEBIAN-CVE-2013-4392systemd@252.39-1~deb12u2no fix listed
LowGHSA-h67p-54hq-rp68js-yaml@4.1.14.2.0
LowGHSA-q6j5-fjx5-2mc3pnpm@10.33.010.34.1
LowGHSA-6v5v-wf23-fmfqmarkdown-it@14.1.114.2.0
LowDEBIAN-CVE-2026-78408util-linux@2.38.1-5+deb12u3no fix listed
LowGHSA-3f6p-5ww8-9rcrmysql2@3.14.13.22.0
LowDEBIAN-CVE-2026-41989libgcrypt20@1.10.1-31.10.1-3+deb12u1
LowGHSA-3jxr-9vmj-r5cpbrace-expansion@2.0.22.1.2
LowGHSA-76mc-f452-cxcmdompurify@3.4.13.4.7
LowGHSA-54hh-g5mx-jqcppnpm@10.33.010.34.0
LowGHSA-p88m-4jfj-68fvundici@6.25.06.27.0
LowGO-2026-4981stdlib@go1.24.61.25.10
LowDEBIAN-CVE-2023-31439systemd@252.39-1~deb12u2no fix listed
LowGHSA-vmf3-w455-68vhtar@7.5.137.5.16
LowGHSA-8988-4f7v-96qf@opentelemetry/core@2.6.12.8.0
LowGO-2026-4977stdlib@go1.24.61.25.10
LowDEBIAN-CVE-2023-31437systemd@252.39-1~deb12u2no fix listed
LowGO-2026-4986stdlib@go1.24.61.25.10
LowGHSA-jwp9-9v96-94mxdecompress@4.2.1no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.1.0latest3 months ago6.41.102302823,092

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/k8s-home-lab-repo/ghost.svg)](https://charts.stackradar.io/charts/k8s-home-lab-repo/ghost)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.