mcp-orchestrator 3.7.86 Helm chart
magertronVerified publisherScored 14 Sept 2026
MCP Orchestrator — Kubernetes-native control plane for managing MCP servers
Version 3.7.86 3 days agoapp version 3.7.86 1Artifact Hub
mcp-orchestrator 3.7.86 deploys 6 container images: curtismager20/mcp-orchestrator, curtismager20/mcp-sync, curtismager20/mcp-chat-daemon, envoyproxy/envoy and 2 more. Across them, 159 findings — 2 critical, 0 high. The highest contribution is UBUNTU-CVE-2019-9515 in grpc 1.51.1-4.1build5, with no fix listed.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| curtismager20/ | 3.7.86 | 20760 | 768 |
| curtismager20/ | 3.7.86 | 0010 | 17 |
| curtismager20/ | 3.7.86 | 0000 | 0 |
| envoyproxy/ | distroless-v1.33.14 | 00718 | 301 |
| curtismager20/ | 3.7.86 | 0004 | 20 |
| library/ | 17-alpine | 00456 | 493 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2026-4946 | stdlib | 1.25.9 |
| Low | UBUNTU-CVE-2026-54370 | acl | no fix listed |
| Low | GO-2026-4603 | stdlib | 1.25.8 |
| Low | DEBIAN-CVE-2010-4756 | glibc | no fix listed |
| Low | GO-2026-6354 | golang.org/ | 0.56.0 |
| Low | GO-2026-4982 | stdlib | 1.25.10 |
| Low | GO-2026-6091 | stdlib | 1.25.13 |
| Low | UBUNTU-CVE-2024-56433 | shadow | no fix listed |
| Low | UBUNTU-CVE-2026-5419 | gnutls28 | 3.8.3-1.1ubuntu3.6+Fips1.2 |
| Low | GO-2026-4864 | stdlib | 1.25.9 |
| Low | GO-2026-4865 | stdlib | 1.25.9 |
| Low | GO-2026-4869 | stdlib | 1.25.9 |
| Low | GO-2026-4340 | stdlib | 1.24.12 |
| Low | GO-2025-4175 | stdlib | 1.24.11 |
| Low | DEBIAN-CVE-2026-18374 | glibc | no fix listed |
| Low | UBUNTU-CVE-2026-86144 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-69184 | c-ares | no fix listed |
| Low | UBUNTU-CVE-2026-69186 | c-ares | no fix listed |
| Low | GO-2026-4970 | stdlib | 1.25.12 |
| Low | GO-2026-4602 | stdlib | 1.25.8 |
| Low | UBUNTU-CVE-2026-18508 | tar | no fix listed |
| Low | UBUNTU-CVE-2026-41990 | libgcrypt20 | 1.12.0-2ubuntu0.1~Fips1~rc11 |
| Low | UBUNTU-CVE-2022-3219 | gnupg2 | no fix listed |
| Low | UBUNTU-CVE-2025-6140 | spdlog | no fix listed |
| Low | DEBIAN-CVE-2026-89092 | glibc | no fix listed |
| Low | GO-2026-5024 | golang.org/ | 0.44.0 |
| Low | UBUNTU-CVE-2026-18477 | tar | no fix listed |
| Low | DEBIAN-CVE-2026-19499 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-19542 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-77117 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-80489 | glibc | no fix listed |
| Low | GO-2026-5841 | github.com/ | 1.18.7 |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | UBUNTU-CVE-2026-40228 | systemd | no fix listed |
| Low | UBUNTU-CVE-2026-86137 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-86141 | libxml2 | no fix listed |
| Low | DEBIAN-CVE-2026-6368 | glibc | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 3.8.0latest | — | 3.8.00 | — | — |
| 3.7.92 | yesterday | 3.7.92 | 2019138 | 1,599 |
| 3.7.86 | 3 days ago | 3.7.86 | 2019138 | 1,599 |
| 3.7.84 | 4 days ago | 3.7.84 | 2019138 | 1,599 |
| 3.7.81 | 5 days ago | 3.7.81 | 2019148 | 1,640 |
| 3.7.69 | 6 days ago | 3.7.69 | 2019147 | 1,634 |
| 3.7.66 | 6 days ago | 3.7.66 | 2019147 | 1,634 |
| 3.7.57 | 7 days ago | 3.7.57 | 001174 | 794 |
| 3.7.52 | 9 days ago | 3.7.52 | 001174 | 794 |
| 3.7.29 | 10 days ago | 3.7.29 | 001174 | 794 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.