StackRadar

dify 0.5.1 Helm chart

kubeblocksVerified publisher

Scored 14 Sept 2026

A Helm chart for Dify

Version 0.5.1 1 year agoapp version 0.6.11 1Artifact Hub

dify 0.5.1 deploys 5 container images: langgenius/dify-api, langgenius/dify-web, langgenius/dify-sandbox, bitnami/postgresql and 1 more. Across the 3 measured, 1,709 findings9 critical, 20 high 2 on CISA KEV. The highest contribution is GHSA-f82v-jwr5-mffw in next 14.1.0, fixed in 14.2.25.

Radar Score

20,4039203111,368

1,709 findings over 3 of 5 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

5 images
ImageTagVulnerabilitiesRadar Score
langgenius/dify-api×20.6.1151020792613,525
langgenius/dify-web0.6.111626861,793
langgenius/dify-sandbox0.2.034783565,085
bitnami/postgresql16.3.0-debian-12-r4unmeasured
bitnami/redis7.2.4-debian-12-r13unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

1,118 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2023-5441vim@2:9.0.1378-2no fix listed
LowALPINE-CVE-2023-42363busybox@1.36.1-r151.36.1-r17
LowDEBIAN-CVE-2026-1965curl@7.88.1-10+deb12u5no fix listed
LowDEBIAN-CVE-2022-0563util-linux@2.38.1-5+deb12u1no fix listed
LowDEBIAN-CVE-2023-1264vim@2:9.0.1378-2no fix listed
LowDEBIAN-CVE-2025-3576krb5@1.20.1-2+deb12u11.20.1-2+deb12u4
LowDEBIAN-CVE-2026-4878libcap2@1:2.66-41:2.66-4+deb12u3
LowGHSA-rgj7-g3m4-5g8csharp@0.33.20.35.4
LowDEBIAN-CVE-2026-11979libxml2@2.9.14+dfsg-1.3~deb12u1no fix listed
LowDEBIAN-CVE-2023-2908tiff@4.5.0-6+deb12u14.5.0-6+deb12u2
LowDEBIAN-CVE-2026-7168curl@7.88.1-10+deb12u57.88.1-10+deb12u15
LowGHSA-v2v4-37r5-5v8gip-address@9.0.510.1.1
LowDEBIAN-CVE-2026-85152node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3no fix listed
LowDEBIAN-CVE-2023-25433tiff@4.5.0-6+deb12u14.5.0-6+deb12u2
LowDEBIAN-CVE-2024-24758node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3no fix listed
LowPYSEC-2026-2104aiohttp@3.9.53.14.0
LowDEBIAN-CVE-2026-86140libxml2@2.9.14+dfsg-1.3~deb12u1no fix listed
LowDEBIAN-CVE-2023-26966tiff@4.5.0-6+deb12u14.5.0-6+deb12u2
LowGO-2024-2600stdlib@go1.20.61.21.8
LowDEBIAN-CVE-2026-57456vim@2:9.0.1378-2no fix listed
LowALPINE-CVE-2023-42366busybox@1.36.1-r151.36.1-r16
LowDEBIAN-CVE-2026-58040nodejs@18.19.0+dfsg-6~deb12u1no fix listed
LowGHSA-28wg-ghj8-5hjvnanoid@3.3.63.3.16
LowDEBIAN-CVE-2026-21714nodejs@18.19.0+dfsg-6~deb12u118.20.4+dfsg-1~deb12u2
LowDEBIAN-CVE-2026-3783curl@7.88.1-10+deb12u57.88.1-10+deb12u15
LowDEBIAN-CVE-2026-4873curl@7.88.1-10+deb12u5no fix listed
LowDEBIAN-CVE-2026-84933node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3no fix listed
LowDSA-6189-1libpng1.6@1.6.39-21.6.39-2+deb12u4
LowDEBIAN-CVE-2026-12706ffmpeg@7:5.1.4-0+deb12u17:5.1.9-0+deb12u1
LowDEBIAN-CVE-2026-38343ffmpeg@7:5.1.4-0+deb12u17:5.1.9-0+deb12u1
LowGO-2024-2609stdlib@go1.20.61.21.8
LowDEBIAN-CVE-2026-34743xz-utils@5.4.1-0.25.4.1-1+deb12u1
LowGO-2024-3107stdlib@go1.20.61.22.7
LowDEBIAN-CVE-2026-5704tar@1.34+dfsg-1.2+deb12u1no fix listed
LowDEBIAN-CVE-2023-6604ffmpeg@7:5.1.4-0+deb12u17:5.1.7-0+deb12u1
LowDEBIAN-CVE-2026-66038ffmpeg@7:5.1.4-0+deb12u1no fix listed
LowDEBIAN-CVE-2023-45913mesa@22.3.6-1+deb12u1no fix listed
LowGHSA-6hr6-w5qg-qmwgh2@4.1.04.4.1
LowDEBIAN-CVE-2026-42307vim@2:9.0.1378-2no fix listed
LowALPINE-CVE-2023-42365busybox@1.36.1-r151.36.1-r19
LowDEBIAN-CVE-2026-22693harfbuzz@6.0.0+dfsg-3no fix listed
LowDEBIAN-CVE-2024-36613ffmpeg@7:5.1.4-0+deb12u17:5.1.5-0+deb12u1
LowGHSA-pq67-6m6q-mj2vurllib3@2.2.12.5.0
LowGHSA-2v37-7h3g-55p8nanoid@3.3.63.3.18
LowDEBIAN-CVE-2026-59858vim@2:9.0.1378-2no fix listed
LowDEBIAN-CVE-2026-3184util-linux@2.38.1-5+deb12u1no fix listed
LowGHSA-37mw-44qp-f5jmtransformers@4.35.24.52.1
LowGHSA-jjph-296x-mrcrtransformers@4.35.24.51.0
LowGHSA-q2wp-rjmx-x6x9transformers@4.35.24.51.0
LowDEBIAN-CVE-2026-5673libtheora@1.1.1+dfsg.1-16.1+b1no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.5.1latest1 year ago0.6.119203111,36820,403

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubeblocks/dify.svg)](https://charts.stackradar.io/charts/kubeblocks/dify)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.