StackRadar

mlflow Helm chart

kelvins

Scored 14 Sept 2026

A Helm chart to deploy Mlflow server using MinIO as storage and PostgreSQL as database.

Latest 0.4.0 4 years agoapp version 1.26.1 0Artifact Hub

mlflow 0.4.0 deploys 3 container images: bitnami/minio, kelvinsp/mlflow and bitnami/postgresql. Across the 1 measured, 247 findings5 critical, 5 high 1 on CISA KEV. The highest contribution is GHSA-7gwp-5pfp-969j in mlflow 1.26.1, fixed in 3.15.0.

Radar Score

4,1565595142

247 findings over 1 of 3 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
bitnami/minio2022.6.3-debian-10-r0unmeasured
kelvinsp/mlflow1.26.155951424,156
bitnami/postgresql14.3.0-debian-10-r22unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

247 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumGHSA-gq3w-7jj3-x7grmlflow@1.26.13.8.0rc0
MediumGHSA-v973-fxgf-6xhpmako@1.2.01.2.2
MediumGHSA-q2r8-vmq7-fpx2mlflow@1.26.13.8.0rc0
MediumGHSA-4qq5-mxxx-m6ggmlflow@1.26.12.8.0
MediumGHSA-ffw3-6378-cqgpmlflow@1.26.12.6.0
MediumGHSA-hvc6-42vf-jhf8mlflow@1.26.12.9.2
MediumGHSA-6xj8-rrqx-r4cvmlflow@1.26.12.22.0rc0
MediumGHSA-6749-m5cp-6cg7mlflow@1.26.12.10.0
MediumDLA-3477-1python3.7@3.7.3-2+deb10u33.7.3-2+deb10u5
MediumGHSA-v945-r3rc-6fjmmlflow@1.26.12.9.2
MediumGHSA-wv8q-4f85-2p8pmlflow@1.26.12.9.2
MediumGHSA-j8r2-6x86-q33qrequests@2.27.12.31.0
MediumDSA-4944-1krb5@1.17-3+deb10u11.17-3+deb10u2
MediumPYSEC-2026-3952gitpython@3.1.273.1.54
MediumGHSA-v9hf-5j83-6xpppymysql@1.0.21.1.1
MediumPYSEC-2023-192urllib3@1.26.92.0.6
MediumGHSA-cxfr-5q3r-2rc2mlflow@1.26.12.9.2
MediumGHSA-956x-8gvw-wg5vgitpython@3.1.273.1.51
MediumGHSA-xch3-2f9x-wh9fmlflow@1.26.13.8.0rc0
MediumGHSA-pqcv-qw2r-r859mlflow@1.26.1no fix listed
MediumGHSA-xg9f-g7g7-2323werkzeug@2.1.22.2.3
MediumGHSA-hq88-wg7q-gp4gmlflow@1.26.12.10.0
MediumPYSEC-2024-60idna@3.33.7
MediumGHSA-3v79-q7ph-j75hmlflow@1.26.12.10.0
MediumDSA-4942-1systemd@241-7~deb10u7241-7~deb10u8
MediumPYSEC-2026-2161gitpython@3.1.273.1.47
MediumGHSA-m2qf-hxjv-5gpqflask@2.1.22.2.5
MediumGHSA-8gq9-2x98-w8hfprotobuf@4.21.14.21.6
MediumGHSA-vhcx-3pq2-4fvcmlflow@1.26.13.9.0rc0
MediumGHSA-2xpw-w6gg-jr37urllib3@1.26.92.6.0
MediumGHSA-gm62-xv2j-4w53urllib3@1.26.92.6.0
MediumGHSA-ghv6-9r9j-wh4jmlflow@1.26.1no fix listed
MediumGHSA-q34m-jh98-gwm2werkzeug@2.1.23.0.6
MediumGHSA-vwhf-3v6x-wff8mlflow@1.26.12.9.0
MediumGHSA-5mvj-wmgj-7q8cmlflow@1.26.1no fix listed
MediumGHSA-fhff-qmm8-h2fpmlflow@1.26.13.9.0rc0
MediumPYSEC-2023-221werkzeug@2.1.22.3.8
MediumGHSA-r9mr-m37c-5fr3gitpython@3.1.273.1.54
MediumPYSEC-2024-230certifi@2022.5.18.12024.7.4
MediumGHSA-76cg-cfhx-373fmlflow@1.26.1no fix listed
MediumGHSA-x38x-g6gr-jqffmlflow@1.26.1no fix listed
MediumGHSA-wc6j-5g83-xfm6mlflow@1.26.12.0.0rc0
MediumGHSA-43c4-9qgj-x742mlflow@1.26.1no fix listed
MediumGHSA-7p8j-qv6x-f4g4mlflow@1.26.1no fix listed
MediumGHSA-wf7f-8fxf-xfxcmlflow@1.26.1no fix listed
MediumDLA-3530-1openssl@1.1.1d-0+deb10u61.1.1n-0+deb10u6
MediumDLA-3213-1krb5@1.17-3+deb10u11.17-3+deb10u5
MediumGHSA-2h4p-vjrc-8xpqmako@1.2.01.3.12
MediumGHSA-284h-m62q-gf8wgitpython@3.1.273.1.59
MediumGHSA-g35p-px32-whv6mlflow@1.26.13.11.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.4.0latest4 years ago1.26.155951424,156

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kelvins/mlflow.svg)](https://charts.stackradar.io/charts/kelvins/mlflow)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.