StackRadar

servarr Helm chart

kubitodevVerified publisher

Scored 14 Sept 2026

Kubito Servarr Helm Chart

Latest 1.5.2 2 months agodeploys tag 1.4.5 7Artifact Hub

servarr 1.5.2 deploys 10 container images: lscr.io/linuxserver/bazarr, ghcr.io/flaresolverr/flaresolverr, lscr.io/linuxserver/jellyfin, ghcr.io/seerr-team/seerr and 6 more. Across the 3 measured, 273 findings0 critical, 2 high 1 on CISA KEV. The highest contribution is GHSA-r5fr-rjxr-66jc in lodash-es 4.17.23, fixed in 4.18.0.

Radar Score

3,0040238233

273 findings over 3 of 10 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

10 images
ImageTagVulnerabilitiesRadar Score
lscr.io/linuxserver/bazarr1.4.5unmeasured
ghcr.io/flaresolverr/flaresolverrv3.3.210114821,013
lscr.io/linuxserver/jellyfin10.10.1unmeasured
ghcr.io/seerr-team/seerrlatest01241511,991
library/busybox×3latest00000
lscr.io/linuxserver/lidarr2.7.1unmeasured
lscr.io/linuxserver/prowlarr1.25.4unmeasured
lscr.io/linuxserver/qbittorrent4.6.7unmeasured
lscr.io/linuxserver/radarr5.14.0unmeasured
lscr.io/linuxserver/sonarr4.0.10unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

233 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-vxpw-j846-p89qundici@6.25.06.27.0
LowGHSA-62hf-57xw-28j9axios@1.15.01.15.1
LowALPINE-CVE-2026-14456openssl@3.5.6-r03.5.8-r0
LowGHSA-34x7-hfp2-rc4vtar@6.2.17.5.7
LowALPINE-CVE-2026-9076openssl@3.5.6-r03.5.7-r0
LowGHSA-q8qp-cvcw-x6jjaxios@1.15.01.15.2
LowGHSA-3g43-6gmg-66jwaxios@1.15.01.15.2
LowGHSA-777c-7fjr-54vfaxios@1.15.01.16.0
LowGHSA-hfxv-24rg-xrqfaxios@1.15.01.16.0
LowGHSA-j5f8-grm9-p9fcaxios@1.15.01.16.0
LowGHSA-q3j6-qgpj-74h6fast-uri@3.1.03.1.1
LowGHSA-rgw5-rvv9-x895brace-expansion@5.0.45.0.9
LowGHSA-9cx6-37pm-9jffhandlebars@4.7.84.7.9
LowALPINE-CVE-2026-63072openssl@3.5.6-r03.5.8-r0
LowALPINE-CVE-2026-45445openssl@3.5.6-r03.5.7-r0
LowDLA-3907-1sqlite3@3.34.1-33.34.1-3+deb11u1
LowGHSA-6g55-p6wh-862qpostcss@8.4.318.5.12
LowGHSA-pmwg-cvhr-8vh7axios@1.15.01.15.1
LowGHSA-w5vr-8v7q-w6rvbaseline-browser-mapping@2.10.232.11.0
LowGHSA-qffp-2rhf-9h96tar@6.2.17.5.10
LowGHSA-22p9-wv53-3rq4linkify-it@5.0.05.0.1
LowGHSA-23hp-3jrh-7fpwtar@7.5.137.5.19
LowGHSA-52cp-r559-cp3mjs-yaml@4.1.14.3.0
LowGHSA-hmw2-7cc7-3qxxform-data@4.0.54.0.6
LowALPINE-CVE-2026-54874openssl@3.5.6-r03.5.8-r0
LowGHSA-7r86-cg39-jmmjminimatch@9.0.59.0.7
LowALPINE-CVE-2026-42766openssl@3.5.6-r03.5.7-r0
LowGHSA-8qq5-rm4j-mr97tar@6.2.17.5.3
LowALPINE-CVE-2026-63075openssl@3.5.6-r03.5.8-r0
LowGHSA-rcmh-qjqh-p98vnodemailer@6.9.167.0.11
LowGHSA-v39h-62p7-jpjcfast-uri@3.1.03.1.2
LowGHSA-23c5-xmqv-rm74minimatch@9.0.59.0.7
LowGHSA-qpx9-hpmf-5gmwunderscore@1.13.71.13.8
LowGHSA-mh99-v99m-4gvgbrace-expansion@5.0.45.0.8
LowGHSA-4cwx-7wf7-3272undici@8.1.08.9.0
LowGHSA-vmh5-mc38-953gundici@8.1.08.5.0
LowGHSA-w27v-7q3p-w38rsvgo@3.3.33.3.5
LowGHSA-73wf-gq98-2v4gbrowserslist@4.28.24.28.7
LowGHSA-v2hh-gcrm-f6hxfast-uri@3.1.03.1.4
LowGHSA-8x88-c5mf-7j5wtar@7.5.137.5.18
LowGHSA-v245-v573-v5vmlinkify-it@5.0.05.0.2
LowGHSA-38rv-x7px-6hhqundici@8.1.08.5.0
LowGHSA-mm7p-fcc7-pg87nodemailer@6.9.167.0.7
LowGHSA-c2c7-rcm5-vvqjpicomatch@4.0.34.0.4
LowGHSA-q8wf-6r8g-63chnext@16.2.616.2.11
LowDLA-3878-1libxml2@2.9.10+dfsg-6.7+deb11u42.9.10+dfsg-6.7+deb11u5
LowGHSA-mwp4-54f8-5fhrip-address@10.2.010.3.1
LowGHSA-wf93-45jw-7689pip@24.026.1.2
LowALPINE-CVE-2026-75803openssl@3.5.6-r03.5.8-r0
LowGHSA-6chq-wfr3-2hj9axios@1.15.01.15.1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.5.2latest2 months ago1.4.502382333,004

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubitodev/servarr.svg)](https://charts.stackradar.io/charts/kubitodev/servarr)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.