StackRadar

gitlab 4.2.3 Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Web-based Git-repository manager with wiki and issue-tracking features.

Version 4.2.3 5 years agoapp version 13.2.2 0Artifact Hub

gitlab 4.2.3 deploys 17 container images: gitlab/gitlab-runner, mirrorgitlabcontainers/alpine-certificates, library/busybox, mirrorgitlabcontainers/gitlab-shell and 13 more. Across the 14 measured, 2,657 findings5 critical, 80 high 18 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

38,1335807271,845

2,657 findings over 14 of 17 images measured

KEV ×18 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

17 images
ImageTagVulnerabilitiesRadar Score
gitlab/gitlab-runner×2alpine-v13.2.1211841974,526
mirrorgitlabcontainers/alpine-certificates×720171114-r3001029
library/busybox×91.31.100000
mirrorgitlabcontainers/gitlab-shellv13.3.007662163,823
mirrorgitlabcontainers/gitlab-sidekiq-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-task-runner-ce×2v13.2.21121131995,119
mirrorgitlabcontainers/gitlab-webservice-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-workhorse-cev13.2.206652143,719
minio/minioRELEASE.2017-12-28T01-21-00Z0490480
kubesphere/nginx-ingress-controller0.21.000000
mirrorgooglecontainers/defaultbackend-amd641.4not yet scanned
mirrorgitlabcontainers/gitlab-container-registryv2.9.1-gitlab05491963,122
mirrorgitlabcontainers/gitalyv13.2.20121052905,548
bitnami/postgresql11.7.0unmeasured
bitnami/redis5.0.7-debian-9-r50unmeasured
minio/mcRELEASE.2018-07-13T00-53-22Z001029
mirrorgitlabcontainers/kubectl1.13.1201241632,132

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

652 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGO-2026-4970stdlib@go1.13.91.25.12
LowGHSA-jfvp-7x6p-h2pvgithub.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.1.14
LowGO-2026-5027golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.55.0
LowGO-2026-5029golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.55.0
LowGO-2026-5030golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.55.0
LowGHSA-58qw-9mgm-455vpip@20.1.126.1
LowGHSA-j6gc-792m-qgm2activesupport@6.0.3.16.1.7.1
LowGHSA-p84v-45xj-wwqjactionpack@6.0.3.16.1.7.1
LowGHSA-rqv2-275x-2jq5rack@2.0.92.0.9.2
LowGHSA-xj5v-6v4g-jfw6rack@2.0.92.2.8.1
LowGO-2026-4602stdlib@go1.13.91.25.8
LowGHSA-vfm5-rmrh-j26vactionpack@6.0.3.17.0.8.7
LowGHSA-93pm-5p5f-3ghxrack@2.0.92.0.9.2
LowGHSA-mmmm-chjf-jmvwgitaly@13.2.0.pre.rc213.3.9
LowGHSA-v55j-83pf-r9cqactionview@6.0.3.17.2.3.1
LowGHSA-c6qg-cjj8-47qprack@2.0.92.2.6.4
LowGHSA-23c2-gwp5-pxw9globalid@0.4.21.0.1
LowGO-2026-5024golang.org/x/sys@v0.0.0-20200113162924-86b910548bc10.44.0
LowGHSA-xjvp-4fhw-gc47github.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.3.6
LowDLA-2424-1tzdata@2019c-0+deb9u12020d-0+deb9u1
LowDLA-2509-1tzdata@2019c-0+deb9u12020e-0+deb9u1
LowDLA-2542-1tzdata@2019c-0+deb9u12021a-0+deb9u1
LowDLA-2593-1ca-certificates@20161130+nmu1+deb9u120200601~deb9u2
LowDLA-2759-1gnutls28@3.5.8-5+deb9u43.5.8-5+deb9u6
LowDLA-2761-1openssl1.0@1.0.2u-1~deb9u11.0.2u-1~deb9u5
LowDLA-2797-1tzdata@2019c-0+deb9u12021a-0+deb9u2
LowDLA-2948-1debian-archive-keyring@2017.5+deb9u12017.5+deb9u2
LowDLA-2963-1tzdata@2019c-0+deb9u12021a-0+deb9u3
LowDLA-3051-1tzdata@2019c-0+deb9u12021a-0+deb9u4
LowGO-2022-0379github.com/docker/distribution@v2.7.0+incompatible2.8.0+incompatible
LowGO-2022-0396github.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.0.0-rc91
LowGO-2023-2153google.golang.org/grpc@v1.24.01.56.3
LowGO-2026-5932golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550no fix listed
LowGO-2026-6061google.golang.org/grpc@v1.24.01.82.1
LowGO-2026-6278github.com/gorilla/websocket@v1.4.01.5.3
LowGHSA-m8cg-xc2p-r3fcgithub.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.1.5
LowGHSA-7f33-f4f5-xwgwgithub.com/aws/aws-sdk-go@v1.31.71.34.0
LowGHSA-8678-w3jw-xfc2nokogiri@1.10.91.19.4
LowGHSA-vvfq-8hwr-qm4mnokogiri@1.10.91.18.3
LowGHSA-6vgw-5pg2-w6jppip@20.1.126.0
LowGHSA-77vh-xpmg-72qhgithub.com/opencontainers/image-spec@v1.0.01.0.2
LowGHSA-qq97-vm5h-rrhggithub.com/docker/distribution@v2.7.0+incompatible2.8.0
LowGHSA-6wx8-w4f5-wwcrconcurrent-ruby@1.1.61.3.7
LowGHSA-4mrv-5p47-p938msgpack@1.3.11.8.2
LowGHSA-5w6v-399v-w3ccnokogiri@1.10.91.18.8
LowGHSA-wfpw-mmfh-qq69nokogiri@1.10.91.19.4
LowGHSA-r95h-9x8f-r3f7nokogiri@1.10.91.16.5
LowGHSA-5cpq-8wj7-hf2vcryptography@3.041.0.0
LowGHSA-g54h-m393-cpwqgithub.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.0.0-rc91
LowGHSA-gmq2-39ff-f5qggithub.com/cloudflare/tableflip@v1.2.1-0.20200514155827-4baec9811f2b1.2.2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.2.3latest5 years ago13.2.25807271,84538,133

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/gitlab.svg)](https://charts.stackradar.io/charts/kubesphere/gitlab)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.