StackRadar

forklift 0.3.0 Helm chart

kubevirt-forkliftVerified publisher

Scored 14 Sept 2026

Forklift — VM migration from VMware/oVirt/OpenStack to KubeVirt

Version 0.3.0app version release-2.12 0Artifact Hub

forklift 0.3.0 deploys 2 container images: quay.io/kubev2v/forklift-operator and openresty/openresty. Across them, 121 findings0 critical, 2 high. The highest contribution is ALPINE-CVE-2018-18312 in perl 5.42.2-r0, fixed in 5.26.3-r0. Chart.yaml declares kubeVersion >=1.30.0-0; rendered for Kubernetes 1.30.0.

Radar Score

1,417022198

121 findings over 2 of 2 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
quay.io/kubev2v/forklift-operatorrelease-2.1200037298
openresty/openresty1.31.1.1-1-alpine-fat0221611,119

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

98 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2026-8926curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-14456openssl@3.5.6-r03.5.8-r0
LowALPINE-CVE-2026-11352curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-9076openssl@3.5.6-r03.5.7-r0
LowALPINE-CVE-2026-82209curl@8.19.0-r08.22.0-r0
LowRHSA-2026:59009python3.12@3.12.13-3.el9_8.10:3.12.14-1.el9_8
LowALPINE-CVE-2026-80255curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-11564curl@8.19.0-r08.22.0-r0
LowGHSA-vp52-pcj8-j9qcgoogle.golang.org/grpc@v1.79.31.83.1
LowALPINE-CVE-2026-13608curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-5773curl@8.19.0-r08.20.0-r0
LowALPINE-CVE-2026-63072openssl@3.5.6-r03.5.8-r0
LowRHSA-2026:55440glib2@2.68.4-19.el9_8.20:2.68.4-19.el9_8.9
LowALPINE-CVE-2026-11586curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-45445openssl@3.5.6-r03.5.7-r0
LowRHSA-2026:55439curl@7.76.1-40.el90:7.76.1-40.el9_8.5
LowALPINE-CVE-2026-80230curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-76641expat@2.7.5-r02.8.4-r0
LowALPINE-CVE-2026-54874openssl@3.5.6-r03.5.8-r0
LowALPINE-CVE-2026-42766openssl@3.5.6-r03.5.7-r0
LowALPINE-CVE-2026-9546curl@8.19.0-r08.22.0-r0
LowRHSA-2026:52674libarchive@3.5.3-9.el9_70:3.5.3-11.el9_8
LowALPINE-CVE-2026-63075openssl@3.5.6-r03.5.8-r0
LowALPINE-CVE-2026-45186expat@2.7.5-r02.8.1-r0
LowALPINE-CVE-2026-33630c-ares@1.34.6-r01.34.8-r0
LowALPINE-CVE-2026-82208curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-12064curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-8932curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-8286curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-75803openssl@3.5.6-r03.5.8-r0
LowALPINE-CVE-2026-8458curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-6253curl@8.19.0-r08.20.0-r0
LowALPINE-CVE-2026-9547curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-6276curl@8.19.0-r08.20.0-r0
LowALPINE-CVE-2026-76956expat@2.7.5-r02.8.4-r0
LowALPINE-CVE-2026-9080curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-42767openssl@3.5.6-r03.5.7-r0
LowALPINE-CVE-2026-5545curl@8.19.0-r08.20.0-r0
LowALPINE-CVE-2026-9545curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-76642util-linux@2.41.4-r02.41.6-r0
LowALPINE-CVE-2026-63074openssl@3.5.6-r03.5.8-r0
LowGHSA-g6cj-pr64-35w5cryptography@49.0.050.0.0
LowALPINE-CVE-2026-34181openssl@3.5.6-r03.5.7-r0
LowRHSA-2026:64800glib2@2.68.4-19.el9_8.20:2.68.4-19.el9_8.10
LowRHSA-2026:58936sqlite@3.34.1-10.el9_80:3.34.1-11.el9_8
LowGHSA-qc2q-p7wx-3px3google.golang.org/grpc@v1.79.31.83.1
LowALPINE-CVE-2026-6429curl@8.19.0-r08.20.0-r0
LowRHSA-2026:50147libgcrypt@1.10.0-11.el90:1.10.0-13.el9_8
LowRHSA-2026:61247libxml2@2.9.13-14.el9_8.20:2.9.13-14.el9_8.4
LowALPINE-CVE-2026-7168curl@8.19.0-r08.20.0-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.3.0latestrelease-2.120221981,417

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubevirt-forklift/forklift.svg)](https://charts.stackradar.io/charts/kubevirt-forklift/forklift)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 13 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.