StackRadar

meshery Helm chart

kubesphere-stable

Scored 14 Sept 2026

Meshery chart for deploying Meshery and Meshery's adapters.

Latest 0.5.0 4 years agoApp version not verified against the render 1Artifact Hub

meshery 0.5.0 deploys 13 container images: layer5/meshery-app-mesh, layer5/meshery-consul, layer5/meshery-cpx, layer5/meshery-istio and 9 more. Across the 12 measured, 2,263 findings1 critical, 48 high 14 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

24,6901483321,882

2,263 findings over 12 of 13 images measured

KEV ×14 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

13 images
ImageTagVulnerabilitiesRadar Score
layer5/meshery-app-meshstable-latest05301782,346
layer5/meshery-consulstable-latest04241682,026
layer5/meshery-cpxstable-latest111611843,713
layer5/meshery-istiostable-latest02191221,413
layer5/meshery-kumastable-latest04241301,701
layer5/meshery-linkerdstable-latest03201421,643
layer5/meshery-nginx-smstable-latest05261542,026
layer5/meshery-nsmstable-latest04542453,479
layer5/meshery-operatorstable-latest00163443
gcr.io/kubebuilder/kube-rbac-proxyv0.5.0unmeasured
layer5/meshery-osmstable-latest05301742,281
layer5/meshery-traefik-meshstable-latest04241631,967
layer5/mesherystable-latest01191591,652

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

351 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-jm56-5h66-w453helm.sh/helm/v3@v3.3.13.3.2
LowALPINE-CVE-2025-69418openssl@3.3.3-r03.3.6-r0
LowGO-2026-5024golang.org/x/sys@v0.32.00.44.0
LowGO-2026-6179golang.org/x/mod@v0.24.00.40.0
LowGHSA-xjvp-4fhw-gc47github.com/opencontainers/runc@v0.1.11.3.6
LowDLA-3134-1tzdata@2021a-0+deb10u12021a-0+deb10u7
LowDLA-3161-1tzdata@2021a-0+deb10u12021a-0+deb10u8
LowDLA-3366-1tzdata@2021a-0+deb10u12021a-0+deb10u10
LowDLA-3412-1tzdata@2021a-0+deb10u12021a-0+deb10u11
LowDLA-3684-1tzdata@2021a-0+deb10u12021a-0+deb10u12
LowDLA-3788-1tzdata@2021a-0+deb10u12024a-0+deb10u1
LowDLA-3972-1tzdata@2021a-1+deb11u82024b-0+deb11u1
LowDLA-4085-1tzdata@2021a-1+deb11u82025a-0+deb11u1
LowDLA-4105-1tzdata@2021a-1+deb11u82025b-0+deb11u1
LowDLA-4403-1tzdata@2021a-1+deb11u82025b-0+deb11u2
LowGO-2022-0360github.com/containerd/containerd@v1.3.41.4.12
LowGO-2022-0379github.com/docker/distribution@v2.7.1+incompatible2.8.0+incompatible
LowGO-2022-0396github.com/opencontainers/runc@v0.1.11.0.0-rc91
LowGO-2022-0965k8s.io/apimachinery@v0.0.0-20190313205120-d7deff9243b10.0.0-20190927203648-9ce6eca90e73
LowGO-2022-1107github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce20.10.20+incompatible
LowGO-2023-2048github.com/cyphar/filepath-securejoin@v0.2.30.2.4
LowGO-2023-2153google.golang.org/grpc@v1.54.01.56.3
LowGO-2023-2412github.com/containerd/containerd@v1.7.61.6.26
LowGO-2024-2453github.com/cloudflare/circl@v1.3.31.3.7
LowGO-2024-2567github.com/jackc/pgx/v5@v5.4.35.5.2
LowGO-2024-2846github.com/containerd/containerd@v1.3.41.5.11
LowGO-2024-2914github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce20.10.11+incompatible
LowGO-2025-3787github.com/go-viper/mapstructure/v2@v2.2.12.3.0
LowGO-2026-5693github.com/go-git/go-git/v5@v5.13.25.19.1
LowGO-2026-5841github.com/klauspost/compress@v1.18.01.18.7
LowGO-2026-5884oras.land/oras-go/v2@v2.5.02.6.1
LowGO-2026-5932golang.org/x/crypto@v0.37.0no fix listed
LowGO-2026-6061google.golang.org/grpc@v1.72.01.82.1
LowGO-2026-6278github.com/gorilla/websocket@v1.5.01.5.3
LowGHSA-v994-f8vw-g7j4github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce20.10.9
LowALPINE-CVE-2025-46394busybox@1.37.0-r121.37.0-r14
LowGHSA-4vq8-7jfc-9cvpgithub.com/docker/docker@v24.0.6+incompatible25.0.13
LowGHSA-m8cg-xc2p-r3fcgithub.com/opencontainers/runc@v0.1.11.1.5
LowGHSA-m7cr-m3pv-hgrpgithub.com/go-git/go-git/v5@v5.13.25.19.1
LowGHSA-j88v-2chj-qfwxgithub.com/jackc/pgx/v5@v5.7.25.9.2
LowGHSA-j88v-2chj-qfwxgithub.com/jackc/pgx/v4@v4.17.2no fix listed
LowGHSA-gm2x-2g9h-ccm8github.com/go-git/go-git/v5@v5.13.25.17.1
LowGHSA-5j5w-g665-5m35github.com/containerd/containerd@v1.3.41.4.12
LowGHSA-77vh-xpmg-72qhgithub.com/opencontainers/image-spec@v1.0.11.0.2
LowGHSA-qq97-vm5h-rrhggithub.com/docker/distribution@v2.7.1+incompatible2.8.0
LowALPINE-CVE-2024-58251busybox@1.37.0-r121.37.0-r14
LowGHSA-xf85-363p-868woras.land/oras-go@v1.2.6no fix listed
LowGHSA-xf85-363p-868woras.land/oras-go/v2@v2.5.02.6.1
LowGHSA-c9cp-9c75-9v8cgithub.com/containerd/containerd@v1.3.41.5.11
LowGHSA-g54h-m393-cpwqgithub.com/opencontainers/runc@v0.1.11.0.0-rc91

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.5.0latest4 years ago1483321,88224,690

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere-stable/meshery.svg)](https://charts.stackradar.io/charts/kubesphere-stable/meshery)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.