StackRadar

servarr Helm chart

kubitodevVerified publisher

Scored 14 Sept 2026

Kubito Servarr Helm Chart

Latest 1.5.2 2 months agodeploys tag 1.4.5 7Artifact Hub

servarr 1.5.2 deploys 10 container images: lscr.io/linuxserver/bazarr, ghcr.io/flaresolverr/flaresolverr, lscr.io/linuxserver/jellyfin, ghcr.io/seerr-team/seerr and 6 more. Across the 3 measured, 273 findings0 critical, 2 high 1 on CISA KEV. The highest contribution is GHSA-r5fr-rjxr-66jc in lodash-es 4.17.23, fixed in 4.18.0.

Radar Score

3,0040238233

273 findings over 3 of 10 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

10 images
ImageTagVulnerabilitiesRadar Score
lscr.io/linuxserver/bazarr1.4.5unmeasured
ghcr.io/flaresolverr/flaresolverrv3.3.210114821,013
lscr.io/linuxserver/jellyfin10.10.1unmeasured
ghcr.io/seerr-team/seerrlatest01241511,991
library/busybox×3latest00000
lscr.io/linuxserver/lidarr2.7.1unmeasured
lscr.io/linuxserver/prowlarr1.25.4unmeasured
lscr.io/linuxserver/qbittorrent4.6.7unmeasured
lscr.io/linuxserver/radarr5.14.0unmeasured
lscr.io/linuxserver/sonarr4.0.10unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

233 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-vmf3-w455-68vhtar@7.5.137.5.16
LowDLA-4315-1tiff@4.2.0-1+deb11u54.2.0-1+deb11u7
LowDLA-4259-1systemd@247.3-7+deb11u4247.3-7+deb11u7
LowGHSA-qccp-gfcp-xxvcurllib3@2.2.22.7.0
LowGHSA-5c9x-8gcm-mpgxaxios@1.15.01.15.1
LowGHSA-vf2m-468p-8v99axios@1.15.01.15.1
LowDLA-3951-1curl@7.74.0-1.3+deb11u117.74.0-1.3+deb11u14
LowGHSA-qx2v-qp2m-jg93postcss@8.4.318.5.10
LowDLA-3875-1gnutls28@3.7.1-5+deb11u43.7.1-5+deb11u6
LowGHSA-445q-vr5w-6q77axios@1.15.01.15.1
LowGHSA-2rp8-mm9q-fp49typeorm@0.3.290.3.31
LowDLA-4492-1gnutls28@3.7.1-5+deb11u43.7.1-5+deb11u9
LowGHSA-2x7j-588g-ccc2nodemailer@6.9.169.1.0
LowGHSA-5p4m-2wfm-xmqjjs-yaml@4.1.14.3.1
LowGHSA-jfc7-64v2-mr8c@sigstore/core@2.0.03.2.1
LowGHSA-3p4h-7m6x-2hcmmulter@2.1.12.2.0
LowALPINE-CVE-2026-45446openssl@3.5.6-r03.5.7-r0
LowDLA-4146-1libxml2@2.9.10+dfsg-6.7+deb11u42.9.10+dfsg-6.7+deb11u7
LowDLA-4176-1openssl@1.1.1w-0+deb11u11.1.1w-0+deb11u3
LowGHSA-4mjr-xmp4-gh2gqs@6.14.16.16.0
LowDLA-3930-1libsepol@3.1-13.1-1+deb11u1
LowGHSA-48c2-rrv3-qjmpyaml@1.10.21.10.3
LowDLA-4092-1libcap2@1:2.44-11:2.44-1+deb11u1
LowGHSA-xx6v-rp6x-q39caxios@1.15.01.15.1
LowDLA-4181-1glibc@2.31-13+deb11u102.31-13+deb11u13
LowGHSA-f88m-g3jw-g9cjsharp@0.34.50.35.0
LowGHSA-898c-q2cr-xwhgaxios@1.15.01.16.0
LowGHSA-r7g4-qg5f-qqm2nodemailer@6.9.168.0.8
LowDLA-4065-1krb5@1.18.3-6+deb11u41.18.3-6+deb11u6
LowDLA-4353-1xorg-server@2:1.20.11-1+deb11u132:1.20.11-1+deb11u17
LowPYSEC-2026-2275requests@2.31.02.33.0
LowGHSA-268h-hp4c-crq3nodemailer@6.9.168.0.9
LowDLA-4128-1glib2.0@2.66.8-1+deb11u32.66.8-1+deb11u6
LowGHSA-wqvq-jvpq-h66fnodemailer@6.9.168.0.9
LowALPINE-CVE-2026-42768openssl@3.5.6-r03.5.7-r0
LowDLA-4306-1pam@1.4.0-9+deb11u11.4.0-9+deb11u2
LowGHSA-2qvq-rjwj-gvw9handlebars@4.7.84.7.9
LowDLA-4072-1xorg-server@2:1.20.11-1+deb11u132:1.20.11-1+deb11u15
LowGHSA-cc9r-2j5m-2m83nodemailer@6.9.169.1.0
LowGHSA-wmmp-3585-3rmpnodemailer@6.9.169.1.0
LowDLA-4130-1shadow@1:4.8.1-11:4.8.1-1+deb11u1
LowDLA-4217-1icu@67.1-767.1-7+deb11u1
LowDLA-4396-1libpng1.6@1.6.37-31.6.37-3+deb11u1
LowDLA-4491-1glib2.0@2.66.8-1+deb11u32.66.8-1+deb11u8
LowGHSA-w9m9-85wc-3x92postcss-selector-parser@7.1.17.1.3
LowGHSA-w7fw-mjwx-w883qs@6.14.16.14.2
LowDLA-3990-1avahi@0.8-5+deb11u20.8-5+deb11u3
LowALPINE-CVE-2026-42770openssl@3.5.6-r03.5.7-r0
LowDLA-4287-1libsndfile@1.0.31-21.0.31-2+deb11u1
LowDLA-4508-1nss@2:3.61-1+deb11u32:3.61-1+deb11u5

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.5.2latest2 months ago1.4.502382333,004

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubitodev/servarr.svg)](https://charts.stackradar.io/charts/kubitodev/servarr)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.