StackRadar

tomcat Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Deploy a basic tomcat application server with sidecar as web archive container

Latest 0.4.0-r1 6 years agoapp version 8.5.41 0Artifact Hub

tomcat 0.4.0-r1 deploys 2 container images: ananwaresystems/webarchive and library/tomcat. Across them, 46 findings4 critical, 7 high 2 on CISA KEV. The highest contribution is ALPINE-CVE-2020-15999 in freetype 2.9.1-r2, fixed in 2.9.1-r3.

Radar Score

1,383472312

46 findings over 2 of 2 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
ananwaresystems/webarchive1.000000
library/tomcat8.5.41-alpine4723121,383

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

46 distinct across the version’s images
SeverityAdvisoryPackageFixed in
CriticalALPINE-CVE-2020-15999KEVfreetype@2.9.1-r22.9.1-r3
CriticalALPINE-CVE-2019-8457sqlite@3.26.0-r33.28.0-r0
CriticalGHSA-3p2h-wqq4-wf4htomcat-coyote@8.5.41no fix listed
CriticalGHSA-m7jv-hq7h-mq7ctomcat-websocket@8.5.418.5.57
HighGHSA-vf77-8h7g-gghptomcat-coyote@8.5.418.5.56
HighALPINE-CVE-2021-23840openssl@1.1.1b-r11.1.1j-r0
HighGHSA-qppj-fm5r-hxr3KEVtomcat-coyote@8.5.418.5.94
HighALPINE-CVE-2021-3449openssl@1.1.1b-r11.1.1k-r0
HighGHSA-vvw4-rfwf-p6hxtomcat-coyote@8.5.418.5.60
HighGHSA-7w75-32cg-r6g2tomcat-coyote@8.5.418.5.99
HighALPINE-CVE-2019-12900bzip2@1.0.6-r61.0.6-r7
MediumGHSA-f268-65qc-98vgtomcat-coyote@8.5.418.5.58
MediumALPINE-CVE-2019-5018sqlite@3.26.0-r33.28.0-r0
MediumALPINE-CVE-2019-14697musl@1.1.20-r41.1.20-r5
MediumALPINE-CVE-2019-1551openssl@1.1.1b-r11.1.1d-r2
MediumGHSA-f4qf-m5gf-8jm8tomcat-coyote@8.5.418.5.64
MediumGHSA-wm9w-rjj3-j356tomcat-coyote@8.5.41no fix listed
MediumALPINE-CVE-2020-28196krb5@1.15.5-r01.15.5-r1
MediumALPINE-CVE-2020-11655sqlite@3.26.0-r33.28.0-r3
MediumALPINE-CVE-2021-23841openssl@1.1.1b-r11.1.1j-r0
MediumGHSA-r29c-68gh-xp6xtomcat-coyote@8.5.419.0.118
MediumALPINE-CVE-2020-1971openssl@1.1.1b-r11.1.1i-r0
MediumALPINE-CVE-2019-19244sqlite@3.26.0-r33.28.0-r2
MediumALPINE-CVE-2019-16168sqlite@3.26.0-r33.28.0-r1
MediumALPINE-CVE-2019-2201libjpeg-turbo@1.5.3-r41.5.3-r6
MediumGHSA-7jqf-v358-p8g7tomcat-coyote@8.5.41no fix listed
MediumALPINE-CVE-2019-1549openssl@1.1.1b-r11.1.1d-r0
MediumGHSA-r6j3-px5g-cq3xtomcat-coyote@8.5.418.5.94
MediumALPINE-CVE-2018-14498libjpeg-turbo@1.5.3-r41.5.3-r5
MediumGHSA-25xr-qj8w-c4vftomcat-coyote@8.5.41no fix listed
MediumGHSA-4j3c-42xv-3f84tomcat-coyote@8.5.41no fix listed
MediumGHSA-v682-8vv8-vpwrtomcat-websocket@8.5.418.5.99
MediumALPINE-CVE-2019-19242sqlite@3.26.0-r33.28.0-r2
MediumALPINE-CVE-2019-5094e2fsprogs@1.44.5-r01.44.5-r1
LowALPINE-CVE-2018-1000654libtasn1@4.13-r04.14-r0
LowGHSA-g8pj-r55q-5c2vtomcat-util@8.5.418.5.94
LowALPINE-CVE-2019-5188e2fsprogs@1.44.5-r01.44.5-r2
LowALPINE-CVE-2020-14363libx11@1.6.7-r01.6.12-r0
LowGHSA-563x-q5rq-57qptomcat-coyote@8.5.419.0.116
LowALPINE-CVE-2019-1563openssl@1.1.1b-r11.1.1d-r0
LowGHSA-fpj8-gq4v-p354tomcat-coyote@8.5.41no fix listed
LowGHSA-qq5r-98hh-rxc9tomcat-coyote@8.5.419.0.113
LowALPINE-CVE-2021-23839openssl@1.1.1b-r11.1.1j-r0
LowALPINE-CVE-2020-14344libx11@1.6.7-r01.6.10-r0
LowALPINE-CVE-2019-1547openssl@1.1.1b-r11.1.1d-r0
LowALPINE-CVE-2020-28928musl@1.1.20-r41.1.20-r6

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.4.0-r1latest6 years ago8.5.414723121,383

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/tomcat.svg)](https://charts.stackradar.io/charts/kubesphere/tomcat)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.