StackRadar

servarr 1.5.2 Helm chart

kubitodevVerified publisher

Scored 14 Sept 2026

Kubito Servarr Helm Chart

Version 1.5.2 2 months agodeploys tag 1.4.5 7Artifact Hub

servarr 1.5.2 deploys 10 container images: lscr.io/linuxserver/bazarr, ghcr.io/flaresolverr/flaresolverr, lscr.io/linuxserver/jellyfin, ghcr.io/seerr-team/seerr and 6 more. Across the 3 measured, 273 findings0 critical, 2 high 1 on CISA KEV. The highest contribution is GHSA-r5fr-rjxr-66jc in lodash-es 4.17.23, fixed in 4.18.0.

Radar Score

3,0040238233

273 findings over 3 of 10 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

10 images
ImageTagVulnerabilitiesRadar Score
lscr.io/linuxserver/bazarr1.4.5unmeasured
ghcr.io/flaresolverr/flaresolverrv3.3.210114821,013
lscr.io/linuxserver/jellyfin10.10.1unmeasured
ghcr.io/seerr-team/seerrlatest01241511,991
library/busybox×3latest00000
lscr.io/linuxserver/lidarr2.7.1unmeasured
lscr.io/linuxserver/prowlarr1.25.4unmeasured
lscr.io/linuxserver/qbittorrent4.6.7unmeasured
lscr.io/linuxserver/radarr5.14.0unmeasured
lscr.io/linuxserver/sonarr4.0.10unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

38 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumDLA-3859-1systemd@247.3-7+deb11u4247.3-7+deb11u6
MediumDLA-3898-1nghttp2@1.43.0-1+deb11u11.43.0-1+deb11u2
MediumDLA-3904-1cups@2.3.3op2-3+deb11u62.3.3op2-3+deb11u9
MediumDLA-3942-2openssl@1.1.1w-0+deb11u11.1.1w-0+deb11u2
MediumALPINE-CVE-2026-45447openssl@3.5.6-r03.5.7-r0
MediumGHSA-p293-qw3h-jr36next@16.2.616.3.3
MediumDLA-4097-1vim@2:8.2.2434-3+deb11u12:8.2.2434-3+deb11u2
MediumGHSA-2w6w-674q-4c4qhandlebars@4.7.84.7.9
MediumGHSA-cx63-2mw6-8hw5setuptools@65.5.170.0.0
MediumGHSA-38jv-5279-wg99urllib3@2.2.22.6.3
MediumPYSEC-2025-49setuptools@65.5.178.1.1
MediumALPINE-CVE-2026-63073openssl@3.5.6-r03.5.8-r0
MediumGHSA-m99w-x7hq-7vfjnext@16.2.616.2.11
MediumGHSA-35jp-ww65-95whaxios@1.15.01.16.0
MediumALPINE-CVE-2026-18798openssl@3.5.6-r03.5.8-r0
MediumGHSA-3f84-rpwh-47g6waitress@2.1.23.0.1
MediumGHSA-6gpp-xcg3-4w24next@16.2.616.2.11
MediumALPINE-CVE-2026-63076openssl@3.5.6-r03.5.8-r0
MediumGHSA-pjwm-pj3p-43mvaxios@1.15.01.16.0
MediumGHSA-89xv-2m56-2m9xnext@16.2.616.2.11
MediumALPINE-CVE-2026-42764openssl@3.5.6-r03.5.7-r0
MediumGHSA-2xpw-w6gg-jr37urllib3@2.2.22.6.0
MediumGHSA-gm62-xv2j-4w53urllib3@2.2.22.6.0
MediumGHSA-p9j2-gv94-2wf4next@16.2.616.2.11
MediumALPINE-CVE-2026-34182openssl@3.5.6-r03.5.7-r0
MediumGHSA-f23m-r3pf-42rhlodash-es@4.17.234.18.0
MediumALPINE-CVE-2026-34183openssl@3.5.6-r03.5.7-r0
MediumPYSEC-2024-230certifi@2023.7.222024.7.4
MediumGHSA-vqfr-h8mv-ghfjh11@0.14.00.16.0
MediumALPINE-CVE-2026-34180openssl@3.5.6-r03.5.7-r0
MediumALPINE-CVE-2026-7383openssl@3.5.6-r03.5.7-r0
MediumALPINE-CVE-2026-14457openssl@3.5.6-r03.5.8-r0
MediumGHSA-3mfm-83xf-c92rhandlebars@4.7.84.7.9
MediumGHSA-xhpv-hc6g-r9c6handlebars@4.7.84.7.9
MediumGHSA-9298-4cf8-g4wjwaitress@2.1.23.0.1
MediumGHSA-p92q-9vqr-4j8vaxios@1.15.01.16.0
MediumGHSA-3ppc-4f35-3m26minimatch@9.0.59.0.6
MediumGHSA-pf86-5x62-jrwfaxios@1.15.01.15.1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.5.2latest2 months ago1.4.502382333,004

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubitodev/servarr.svg)](https://charts.stackradar.io/charts/kubitodev/servarr)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.