StackRadar

gitlab Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Web-based Git-repository manager with wiki and issue-tracking features.

Latest 4.2.3 5 years agoapp version 13.2.2 0Artifact Hub

gitlab 4.2.3 deploys 17 container images: gitlab/gitlab-runner, mirrorgitlabcontainers/alpine-certificates, library/busybox, mirrorgitlabcontainers/gitlab-shell and 13 more. Across the 14 measured, 2,657 findings5 critical, 80 high 18 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

38,1335807271,845

2,657 findings over 14 of 17 images measured

KEV ×18 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

17 images
ImageTagVulnerabilitiesRadar Score
gitlab/gitlab-runner×2alpine-v13.2.1211841974,526
mirrorgitlabcontainers/alpine-certificates×720171114-r3001029
library/busybox×91.31.100000
mirrorgitlabcontainers/gitlab-shellv13.3.007662163,823
mirrorgitlabcontainers/gitlab-sidekiq-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-task-runner-ce×2v13.2.21121131995,119
mirrorgitlabcontainers/gitlab-webservice-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-workhorse-cev13.2.206652143,719
minio/minioRELEASE.2017-12-28T01-21-00Z0490480
kubesphere/nginx-ingress-controller0.21.000000
mirrorgooglecontainers/defaultbackend-amd641.4not yet scanned
mirrorgitlabcontainers/gitlab-container-registryv2.9.1-gitlab05491963,122
mirrorgitlabcontainers/gitalyv13.2.20121052905,548
bitnami/postgresql11.7.0unmeasured
bitnami/redis5.0.7-debian-9-r50unmeasured
minio/mcRELEASE.2018-07-13T00-53-22Z001029
mirrorgitlabcontainers/kubectl1.13.1201241632,132

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

652 distinct across the version’s images
SeverityAdvisoryPackageFixed in
CriticalALPINE-CVE-2021-3711openssl@1.1.1g-r01.1.1l-r0
CriticalGHSA-754f-8gm6-c4r2ruby-saml@1.7.21.12.4
CriticalALPINE-CVE-2021-21300git@2.26.2-r02.26.3-r0
HighALPINE-CVE-2022-25236expat@2.2.9-r12.2.10-r2
HighALPINE-CVE-2022-0778openssl@1.1.1g-r01.1.1n-r0
HighGHSA-x4qr-2fvf-3mr5cryptography@3.039.0.1
HighGHSA-xr9x-r78c-5hrmactivestorage@6.0.3.17.2.3.2
HighALPINE-CVE-2018-25032zlib@1.2.11-r31.2.12-r0
HighGHSA-jc36-42cf-vqwjnokogiri@1.10.91.13.4
HighALPINE-CVE-2021-23840openssl@1.1.1g-r01.1.1j-r0
HighALPINE-CVE-2021-3712openssl@1.1.1g-r01.1.1l-r0
HighGHSA-8877-prq4-9xfwactionpack@6.0.3.16.0.3.5
HighGHSA-4vc4-m8qh-g8jmruby-saml@1.7.21.12.4
HighGHSA-45x7-px36-x8w8golang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.0.0-20231218163308-9d2ee975ef9f
HighALPINE-CVE-2022-37434zlib@1.2.11-r31.2.12-r2
HighGHSA-35mm-cc6r-8fjpactionpack@6.0.3.16.0.3.4
HighGHSA-qppj-fm5r-hxr3KEVgolang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.17.0
HighGHSA-59gp-qqm7-cw4jnokogiri@1.10.91.13.2
HighGHSA-4v7x-pqxf-cx7mgolang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.23.0
HighALPINE-CVE-2021-3449openssl@1.1.1g-r01.1.1k-r0
HighALPINE-CVE-2019-3822curl@7.57.0-r07.61.1-r2
HighALPINE-CVE-2018-1000120curl@7.57.0-r07.59.0-r0
HighGHSA-jw9c-mfg7-9rx2ruby-saml@1.7.21.12.3
HighALPINE-CVE-2018-14618curl@7.57.0-r07.61.1-r0
HighGHSA-ffhg-7mh4-33c4golang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.0.0-20200220183623-bac4c82f6975
HighGHSA-jvgm-pfqv-887xbundler@1.16.62.0.0
HighGHSA-pg8v-g4xq-hww9rails-html-sanitizer@1.3.01.4.3
HighALPINE-CVE-2018-1000122curl@7.57.0-r07.59.0-r0
HighDLA-2534-1KEVsudo@1.8.19p1-2.1+deb9u21.8.19p1-2.1+deb9u3
HighDLA-2663-1KEVlibimage-exiftool-perl@10.40-110.40-1+deb9u1
HighDLA-2776-1KEVapache2@2.4.25-3+deb9u92.4.25-3+deb9u11
HighGO-2022-0535KEVstdlib@go1.13.31.12.16
MediumDLA-2907-1apache2@2.4.25-3+deb9u92.4.25-3+deb9u12
MediumALPINE-CVE-2018-0500curl@7.57.0-r07.61.0-r0
MediumGO-2024-2687stdlib@go1.13.91.21.9
MediumGHSA-5cgq-3rg8-m6cvgolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.52.0
MediumALPINE-CVE-2018-16839curl@7.57.0-r07.61.1-r1
MediumDLA-2544-1openldap@2.4.44+dfsg-5+deb9u42.4.44+dfsg-5+deb9u7
MediumDLA-3008-1openssl@1.1.0l-1~deb9u11.1.0l-1~deb9u6
MediumGHSA-22f2-v57c-j9cxrack@2.0.92.2.8.1
MediumGHSA-jw9f-hh49-cvp9nokogiri@1.10.91.11.4
MediumGHSA-cf3w-g86h-35x4carrierwave@1.3.11.3.2
MediumALPINE-CVE-2021-22945curl@7.69.1-r07.79.0-r0
MediumDLA-2952-1openssl@1.1.0l-1~deb9u11.1.0l-1~deb9u5
MediumDLA-2953-1openssl1.0@1.0.2u-1~deb9u11.0.2u-1~deb9u7
MediumALPINE-CVE-2022-25235expat@2.2.9-r12.2.10-r2
MediumALPINE-CVE-2018-1000301curl@7.57.0-r07.60.0-r0
MediumALPINE-CVE-2022-22822expat@2.2.9-r12.2.10-r0
MediumALPINE-CVE-2022-25315expat@2.2.9-r12.2.10-r2
MediumALPINE-CVE-2018-1000300curl@7.57.0-r07.60.0-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.2.3latest5 years ago13.2.25807271,84538,133

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/gitlab.svg)](https://charts.stackradar.io/charts/kubesphere/gitlab)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.