StackRadar

home-assistant 0.5.4 Helm chart

kfirfer

Scored 14 Sept 2026

HomeAssistant is an open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server.

Version 0.5.4 2 years agoapp version 2023.10.3 0Artifact Hub

home-assistant 0.5.4 deploys 1 container image: homeassistant/home-assistant. Across them, 478 findings6 critical, 12 high 1 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 8.3.0-r0, fixed in 8.4.0-r0.

Radar Score

6,44761298361

478 findings over 1 of 1 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
homeassistant/home-assistant2023.10.3612983616,447

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

478 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumGHSA-wj6h-64fc-37mpecdsa@0.18.0no fix listed
MediumGHSA-hx9q-6w63-j58vorjson@3.9.73.11.6
MediumGHSA-rm3j-f69w-wqmqgolang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad0.52.0
MediumGHSA-jm66-cg57-jjv5azure-core@1.29.41.38.0
MediumGHSA-hcg3-q754-cr77golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad0.35.0
MediumGHSA-3rq5-2g8h-59hcdnspython@2.4.22.6.1
MediumGHSA-c6mh-fpjc-4pr3yt-dlp@2023.9.242026.6.9
MediumGHSA-7gcm-g887-7qv7protobuf@4.24.35.29.6
MediumALPINE-CVE-2024-32021git@2.40.1-r02.40.3-r0
MediumPYSEC-2023-246aiohttp@3.8.53.8.6
MediumGO-2022-1144stdlib@go1.17.11.18.9
MediumGHSA-pwhh-q4h6-w599spotipy@2.23.02.25.1
MediumGHSA-6vqw-3v5j-54x4cryptography@41.0.442.0.4
MediumGHSA-63hf-3vf5-4wqfaiohttp@3.8.53.13.4
MediumPYSEC-2026-2191kafka-python@2.0.22.3.2
MediumGHSA-jr27-m4p2-rc6rpyasn1@0.4.80.6.3
LowPYSEC-2026-2132click@8.1.78.3.3
LowALPINE-CVE-2023-43615mbedtls@2.28.4-r02.28.5-r0
LowGHSA-q3qx-c6g2-7pw2aiohttp@3.8.53.9.0
LowGHSA-89gr-r52h-f8rxgolang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad0.52.0
LowALPINE-CVE-2024-37370krb5@1.20.1-r11.20.2-r1
LowALPINE-CVE-2023-38546curl@8.3.0-r08.4.0-r0
LowGHSA-7cx3-6m66-7c5mtornado@6.3.36.5
LowGHSA-jppx-rxg9-jmrxgolang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad0.52.0
LowGHSA-j857-7rvv-vj97jwcrypto@1.5.01.5.6
LowGHSA-5rfv-66g4-jr8hrestrictedpython@6.27.3
LowGO-2021-0263stdlib@go1.17.11.16.10
LowGHSA-44wm-f244-xhp3pillow@10.0.110.3.0
LowGHSA-62p4-gmf7-7g93pillow@10.0.112.3.0
LowGHSA-54jj-px8x-5w5qdeepdiff@6.6.08.6.2
LowGO-2023-1571stdlib@go1.17.11.19.6
LowPYSEC-2026-2098aiohttp@3.8.53.13.4
LowGHSA-p998-jp59-783maiohttp@3.8.53.13.4
LowGHSA-8qpw-xqxj-h4r2aiohttp@3.8.53.9.2
LowGHSA-pq5p-34cr-23v9authlib@1.2.11.6.5
LowGHSA-vx4q-3cr2-7cg2yt-dlp@2023.9.242026.6.9
LowGHSA-6jhg-hg63-jvvfaiohttp@3.8.53.13.3
LowGHSA-2wxc-x7rj-hg8fasyncssh@2.14.02.23.1
LowGHSA-g3cq-j2xw-wf74aiohttp@3.8.53.14.1
LowGO-2022-0435stdlib@go1.17.11.17.9
LowALPINE-CVE-2023-5981gnutls@3.8.0-r23.8.3-r0
LowGHSA-g84x-mcqj-x9qqaiohttp@3.8.53.13.3
LowGHSA-vjc4-5qp5-m44jpillow@10.0.112.3.0
LowGHSA-jj3x-wxrx-4x23aiohttp@3.8.53.13.3
LowGO-2022-0288stdlib@go1.17.11.16.12
LowGHSA-q2x7-8rv6-6q7hjinja2@3.1.23.1.5
LowGHSA-xj96-63gp-2gmrpillow@10.0.112.3.0
LowGO-2023-2102stdlib@go1.17.11.20.10
LowGHSA-mgf9-4vpg-hj56tornado@6.3.36.5.6
LowGHSA-6mq8-rvhq-8wggaiohttp@3.8.53.13.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.5.4latest2 years ago2023.10.3612983616,447

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kfirfer/home-assistant.svg)](https://charts.stackradar.io/charts/kfirfer/home-assistant)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.