vcluster-platform 4.11.2 Helm chart
loftVerified publisherScored 14 Sept 2026
vCluster Platform - Virtual Kubernetes Clusters
Version 4.11.2 6 days agoApp version not verified against the render 2Artifact Hub
vcluster-platform 4.11.2 deploys 1 container image: ghcr.io/loft-sh/vcluster-platform. Across them, 181 findings — 0 critical, 0 high. The highest contribution is GHSA-5cgq-3rg8-m6cv in golang.org/x/crypto v0.47.0, fixed in 0.52.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | 4.11.2 | 0015166 | 1,657 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-89gr-r52h-f8rx | golang.org/ | 0.52.0 |
| Low | ALPINE-CVE-2026-14662 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14662 | postgresql18 | 18.5-r0 |
| Low | GHSA-jppx-rxg9-jmrx | golang.org/ | 0.52.0 |
| Low | ALPINE-CVE-2026-14456 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-14664 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-14664 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14670 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-14670 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-15742 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-15742 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14676 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-14676 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-19385 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-19385 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-14671 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14671 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-14677 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14677 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-14680 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-14680 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-16238 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-16238 | postgresql18 | 18.5-r0 |
| Low | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Low | ALPINE-CVE-2026-32316 | jq | 1.8.2-r0 |
| Low | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-18408 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-18408 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-15741 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-15741 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-76641 | expat | 2.8.4-r0 |
| Low | ALPINE-CVE-2026-54874 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-63075 | openssl | 3.5.8-r0 |
| Low | GHSA-q4h4-gmj2-qvw2 | golang.org/ | 0.52.0 |
| Low | GHSA-w879-237q-wc7r | golang.org/ | 0.52.0 |
| Low | ALPINE-CVE-2026-6464 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-6464 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-14668 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-14668 | postgresql17 | 17.11-r0 |
| Low | GHSA-8xwf-rjm4-xvhv | oras.land/ | 2.6.1 |
| Low | ALPINE-CVE-2026-14679 | postgresql18 | 18.5-r0 |
| Low | ALPINE-CVE-2026-14679 | postgresql17 | 17.11-r0 |
| Low | GHSA-jxpm-75mh-9fp7 | oras.land/ | 2.6.1 |
| Low | ALPINE-CVE-2026-75803 | openssl | 3.5.8-r0 |
| Low | GHSA-c5q2-7r4c-mv6g | gopkg.in/ | no fix listed |
| Low | ALPINE-CVE-2026-40164 | jq | 1.8.2-r0 |
| Low | GHSA-fxhp-mv3v-67qp | oras.land/ | 2.6.2 |
| Low | ALPINE-CVE-2026-39979 | jq | 1.8.2-r0 |
| Low | GHSA-pjcq-xvwq-hhpj | github.com/ | 0.1.1 |
| Low | ALPINE-CVE-2026-76642 | util-linux | 2.42.3-r0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 4.12.0latest | 5 days ago | — | 00780 | 744 |
| 4.11.2 | 6 days ago | — | 0015166 | 1,657 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.