StackRadar

nublado Helm chart

lsst-sqre

Scored 14 Sept 2026

A Helm chart for Kubernetes

Latest 0.9.23 5 years agodeploys tag v0.2 0Artifact Hub

nublado 0.9.23 deploys 5 container images: ericmandel/js9server, lsstsqre/sciplat-hub, jupyterhub/configurable-http-proxy, lsstsqre/wfdispatcher and 1 more. Across the 4 measured, 440 findings0 critical, 4 high. The highest contribution is GHSA-x4qr-2fvf-3mr5 in cryptography 3.4.7, fixed in 39.0.1.

Radar Score

5,78604131305

440 findings over 4 of 5 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

5 images
ImageTagVulnerabilitiesRadar Score
ericmandel/js9serverv0.2unmeasured
lsstsqre/sciplat-hublatest02631102,482
jupyterhub/configurable-http-proxylatest001447756
lsstsqre/wfdispatcherlatest0127741,274
lsstsqre/prepullerlatest0127741,274

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

236 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-xqr8-7jwr-rhp7certifi@2020.12.52023.7.22
LowALPINE-CVE-2026-80230curl@8.19.0-r08.22.0-r0
LowGHSA-c98p-7wgm-6p64tornado@6.16.5.3
LowGHSA-23hp-3jrh-7fpwtar@2.2.17.5.19
LowGHSA-hmw2-7cc7-3qxxform-data@2.0.02.5.6
LowGHSA-jhmp-mqwm-3gq8tornado@6.16.5.3
LowALPINE-CVE-2026-54874openssl@3.5.7-r03.5.8-r0
LowGHSA-9x4q-3gxw-849fjupyterhub@1.3.04.1.6
LowGHSA-7r86-cg39-jmmjminimatch@3.0.33.1.3
LowGHSA-gprj-3p75-f996oauthenticator@0.13.016.3.1
LowGHSA-8qq5-rm4j-mr97tar@2.2.17.5.3
LowALPINE-CVE-2026-9546curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-63075openssl@3.5.7-r03.5.8-r0
LowGHSA-23c5-xmqv-rm74minimatch@3.0.33.1.4
LowGHSA-mh99-v99m-4gvgbrace-expansion@1.1.61.1.17
LowGHSA-r6ph-v2qm-q3c2cryptography@3.4.746.0.5
LowALPINE-CVE-2026-33630c-ares@1.34.6-r01.34.8-r0
LowGHSA-3cwm-7jmm-774wbeaker@1.5.4no fix listed
LowGHSA-8x88-c5mf-7j5wtar@2.2.17.5.18
LowALPINE-CVE-2026-82208curl@8.19.0-r08.22.0-r0
LowGHSA-4hpf-3wq7-5rpris-my-json-valid@2.15.02.17.2
LowGHSA-7r3h-4ph8-w38gjupyterhub@1.3.04.1.0
LowALPINE-CVE-2026-12064curl@8.19.0-r08.22.0-r0
LowGHSA-43fp-rhv2-5gv8certifi@2020.12.52022.12.07
LowALPINE-CVE-2026-8932curl@8.19.0-r08.22.0-r0
LowGHSA-3x9g-8vmp-wqvftornado@6.16.5.6
LowPYSEC-2026-3553cryptography@3.4.749.0.0
LowALPINE-CVE-2026-8286curl@8.19.0-r08.22.0-r0
LowGHSA-wf93-45jw-7689pip@21.0.126.1.2
LowALPINE-CVE-2026-75803openssl@3.5.7-r03.5.8-r0
LowGHSA-p8p7-x288-28g6request@2.75.0no fix listed
LowGHSA-r6q2-hw4h-h46wtar@2.2.17.5.4
LowGHSA-r292-9mhp-454mtar@2.2.17.5.21
LowGHSA-xgmm-8j9v-c9wxpyjwt@2.0.12.13.0
LowGHSA-qjxf-f2mg-c6mctornado@6.16.5.5
LowALPINE-CVE-2026-40164jq@1.8.1-r01.8.2-r0
LowGHSA-h75v-3vvj-5mfjjinja2@2.11.33.1.4
LowALPINE-CVE-2026-39979jq@1.8.1-r01.8.2-r0
LowGHSA-v92g-xgxw-vvmmmako@1.1.41.3.11
LowGHSA-ph34-pc88-72gcnpm@3.10.105.7.1
LowALPINE-CVE-2026-8458curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-6253curl@8.19.0-r08.20.0-r0
LowGHSA-mpf4-983q-p7j4tornado@6.16.5.8
LowGHSA-w9mr-4mfr-499fms@0.7.12.0.0
LowGHSA-m4p7-r5rc-7g4jpyasn1@0.4.80.6.4
LowGHSA-9hjg-9r4m-mvj7requests@2.25.12.32.4
LowGHSA-gxpj-cx7g-858cdebug@2.2.02.6.9
LowGHSA-8ppf-4f7h-5ppjpyasn1@0.4.80.6.4
LowGHSA-hm4w-wwcw-mr6rpyasn1@0.4.80.6.4
LowGHSA-h5c8-rqwp-cp95jinja2@2.11.33.1.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.9.23latest5 years agov0.2041313055,786

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/lsst-sqre/nublado.svg)](https://charts.stackradar.io/charts/lsst-sqre/nublado)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.