StackRadar

nginx-php-fpm Helm chart

kokuwa

Scored 14 Sept 2026

A Helm chart for Kubernetes deploying nginx with php fpm

Latest 0.1.4 7 months agodeploys tag 1.29.0-alpine3.22 1Artifact Hub

nginx-php-fpm 0.1.4 deploys 2 container images: nginxinc/nginx-unprivileged and library/php. Across them, 150 findings0 critical, 1 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.5.1-r0, fixed in 3.5.5-r0.

Radar Score

1,8380144105

150 findings over 2 of 2 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
nginxinc/nginx-unprivileged×21.29.0-alpine3.220129791,291
library/php×28.5.2-fpm-alpine3.22001526547

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

29 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumALPINE-CVE-2026-45447openssl@3.5.1-r03.5.7-r0
MediumALPINE-CVE-2025-49796libxml2@2.13.8-r02.13.9-r0
MediumALPINE-CVE-2025-11187openssl@3.5.1-r03.5.5-r0
MediumALPINE-CVE-2026-63073openssl@3.5.1-r03.5.8-r0
MediumALPINE-CVE-2025-9230openssl@3.5.1-r03.5.4-r0
MediumALPINE-CVE-2026-18798openssl@3.5.1-r03.5.8-r0
MediumALPINE-CVE-2025-9231openssl@3.5.1-r03.5.4-r0
MediumALPINE-CVE-2025-58050pcre2@10.43-r110.46-r0
MediumALPINE-CVE-2025-9086curl@8.14.1-r18.14.1-r2
MediumALPINE-CVE-2025-49794libxml2@2.13.8-r02.13.9-r0
MediumALPINE-CVE-2025-6021libxml2@2.13.8-r02.13.9-r0
MediumALPINE-CVE-2026-63076openssl@3.5.1-r03.5.8-r0
MediumALPINE-CVE-2025-59375expat@2.7.1-r02.7.2-r0
MediumALPINE-CVE-2026-25646libpng@1.6.47-r01.6.55-r0
MediumALPINE-CVE-2026-42764openssl@3.5.1-r03.5.7-r0
MediumALPINE-CVE-2026-34182openssl@3.5.1-r03.5.7-r0
MediumALPINE-CVE-2026-33416libpng@1.6.47-r01.6.56-r0
MediumALPINE-CVE-2026-34183openssl@3.5.1-r03.5.7-r0
MediumALPINE-CVE-2026-31790openssl@3.5.1-r03.5.6-r0
MediumALPINE-CVE-2026-34180openssl@3.5.1-r03.5.7-r0
MediumALPINE-CVE-2026-7383openssl@3.5.1-r03.5.7-r0
MediumALPINE-CVE-2026-14457openssl@3.5.1-r03.5.8-r0
MediumALPINE-CVE-2025-9232openssl@3.5.1-r03.5.4-r0
MediumALPINE-CVE-2026-66046expat@2.7.1-r02.8.4-r0
MediumALPINE-CVE-2026-28388openssl@3.5.1-r03.5.6-r0
MediumALPINE-CVE-2025-69421openssl@3.5.1-r03.5.5-r0
MediumALPINE-CVE-2026-28387openssl@3.5.1-r03.5.6-r0
MediumALPINE-CVE-2026-28389openssl@3.5.1-r03.5.6-r0
MediumALPINE-CVE-2026-28390openssl@3.5.1-r03.5.6-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.1.4latest7 months ago1.29.0-alpine3.2201441051,838

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kokuwa/nginx-php-fpm.svg)](https://charts.stackradar.io/charts/kokuwa/nginx-php-fpm)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.