StackRadar

kcm 1.11.0 Helm chart

kcm

Scored 14 Sept 2026

A Helm chart for KCM core components

Version 1.11.0App version not verified against the render 0Artifact Hub

kcm 1.11.0 deploys 12 container images: ghcr.io/fluxcd/helm-controller, ghcr.io/fluxcd/source-controller, quay.io/reactiveops/rbac-manager, quay.io/jetstack/cert-manager-cainjector and 8 more. Across the 11 measured, 328 findings0 critical, 1 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.5.4-r0, fixed in 3.5.5-r0.

Radar Score

2,8180129298

328 findings over 11 of 12 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

12 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/fluxcd/helm-controllerv1.6.200430315
ghcr.io/fluxcd/source-controllerv1.9.200435351
quay.io/reactiveops/rbac-managerv1.9.5011775973
quay.io/jetstack/cert-manager-cainjectorv1.21.00001491
quay.io/jetstack/cert-manager-controllerv1.21.000022151
quay.io/jetstack/cert-manager-webhookv1.21.000021144
ghcr.io/stakater/reloaderv1.4.190001281
velero/velerov1.18.1unmeasured
ghcr.io/k0rdent/kcm/telemetry1.11.0000960
ghcr.io/k0rdent/kcm/controller1.11.00001382
ghcr.io/fluxcd/flux-cliv2.9.100453479
quay.io/jetstack/cert-manager-startupapicheckv1.21.00001491

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

119 distinct across the version’s images
SeverityAdvisoryPackageFixed in
HighALPINE-CVE-2025-15467openssl@3.5.4-r03.5.5-r0
MediumALPINE-CVE-2026-45447openssl@3.5.4-r03.5.7-r0
MediumALPINE-CVE-2025-11187openssl@3.5.4-r03.5.5-r0
MediumALPINE-CVE-2026-63073openssl@3.5.4-r03.5.8-r0
MediumALPINE-CVE-2026-18798openssl@3.5.4-r03.5.8-r0
MediumALPINE-CVE-2026-63076openssl@3.5.4-r03.5.8-r0
MediumALPINE-CVE-2026-42764openssl@3.5.4-r03.5.7-r0
MediumALPINE-CVE-2026-34182openssl@3.5.4-r03.5.7-r0
MediumALPINE-CVE-2026-34183openssl@3.5.4-r03.5.7-r0
MediumALPINE-CVE-2026-31790openssl@3.5.4-r03.5.6-r0
MediumALPINE-CVE-2026-34180openssl@3.5.4-r03.5.7-r0
MediumALPINE-CVE-2026-7383openssl@3.5.4-r03.5.7-r0
MediumALPINE-CVE-2026-14457openssl@3.5.4-r03.5.8-r0
MediumALPINE-CVE-2026-28388openssl@3.5.4-r03.5.6-r0
MediumALPINE-CVE-2025-69421openssl@3.5.4-r03.5.5-r0
MediumALPINE-CVE-2026-28387openssl@3.5.4-r03.5.6-r0
MediumALPINE-CVE-2026-28389openssl@3.5.4-r03.5.6-r0
MediumALPINE-CVE-2026-28390openssl@3.5.4-r03.5.6-r0
LowALPINE-CVE-2025-69420openssl@3.5.4-r03.5.5-r0
LowALPINE-CVE-2026-14456openssl@3.5.4-r03.5.8-r0
LowALPINE-CVE-2026-9076openssl@3.5.4-r03.5.7-r0
LowGHSA-vp52-pcj8-j9qcgoogle.golang.org/grpc@v1.81.11.83.1
LowALPINE-CVE-2026-63072openssl@3.5.4-r03.5.8-r0
LowALPINE-CVE-2026-45445openssl@3.5.4-r03.5.7-r0
LowALPINE-CVE-2026-31789openssl@3.5.4-r03.5.6-r0
LowALPINE-CVE-2025-69419openssl@3.5.4-r03.5.5-r0
LowALPINE-CVE-2026-54874openssl@3.5.4-r03.5.8-r0
LowALPINE-CVE-2026-42766openssl@3.5.4-r03.5.7-r0
LowALPINE-CVE-2026-63075openssl@3.5.4-r03.5.8-r0
LowALPINE-CVE-2026-22184zlib@1.3.1-r21.3.2-r0
LowALPINE-CVE-2026-75803openssl@3.5.4-r03.5.8-r0
LowALPINE-CVE-2025-15468openssl@3.5.4-r03.5.5-r0
LowGHSA-pjcq-xvwq-hhpjgithub.com/Azure/go-ntlmssp@v0.0.0-20221128193559-754e693213580.1.1
LowGO-2026-4341stdlib@go1.25.51.24.12
LowGHSA-hc8v-wwc9-vgxmgithub.com/go-git/go-git/v5@v5.19.15.19.2
LowGHSA-fxhp-mv3v-67qporas.land/oras-go/v2@v2.6.12.6.2
LowALPINE-CVE-2026-2673openssl@3.5.4-r03.5.6-r0
LowGHSA-f5mr-q85p-6hh6github.com/sigstore/fulcio@v1.8.51.8.6
LowALPINE-CVE-2026-42767openssl@3.5.4-r03.5.7-r0
LowGHSA-qgq7-7hm3-q39jgithub.com/go-git/go-git/v5@v5.19.15.19.2
LowALPINE-CVE-2026-63074openssl@3.5.4-r03.5.8-r0
LowALPINE-CVE-2026-34181openssl@3.5.4-r03.5.7-r0
LowGHSA-5cv4-jp36-h3mwgolang.org/x/net@v0.48.00.55.0
LowALPINE-CVE-2026-40200musl@1.2.5-r101.2.5-r12
LowALPINE-CVE-2025-66199openssl@3.5.4-r03.5.5-r0
LowGHSA-qc2q-p7wx-3px3google.golang.org/grpc@v1.81.11.83.1
LowALPINE-CVE-2026-22796openssl@3.5.4-r03.5.5-r0
LowGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc@v1.81.11.82.1
LowALPINE-CVE-2026-42769openssl@3.5.4-r03.5.7-r0
LowGO-2026-4981stdlib@go1.25.51.25.10

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.11.0latest01292982,818

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kcm/kcm.svg)](https://charts.stackradar.io/charts/kcm/kcm)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 13 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.