StackRadar

mcp-orchestrator 4.0.0 Helm chart

magertronVerified publisher

Scored 2 Oct 2026

MCP Orchestrator — Kubernetes-native control plane for managing MCP servers

Version 4.0.0app version 4.0.00 1Artifact Hub

mcp-orchestrator 4.0.0 deploys 7 container images: curtismager20/mcp-orchestrator, curtismager20/mcp-sync, curtismager20/mcp-chat-daemon, envoyproxy/envoy and 3 more. Across them, 156 findings — 2 critical, 0 high. The highest contribution is UBUNTU-CVE-2019-9515 in grpc 1.51.1-4.1build5, with no fix listed.

Radar Score

1,5602016138

156 findings over 7 of 7 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

7 images
ImageTagVulnerabilitiesRadar Score
curtismager20/mcp-orchestrator4.0.0020866842
curtismager20/mcp-sync4.0.00001017
curtismager20/mcp-chat-daemon4.0.0000000
envoyproxy/envoydistroless-v1.33.1400722363
library/busybox1.3600000
curtismager20/mcp-inventory4.0.00000424
library/postgres×217-alpine00046314

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

132 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2026-86142libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-89157pcre2@10.42-4ubuntu2.1no fix listed
LowGO-2026-4601stdlib@go1.24.61.25.8
LowGO-2026-4977stdlib@go1.24.61.25.10
LowUBUNTU-CVE-2026-89161pcre2@10.42-4ubuntu2.1no fix listed
LowUBUNTU-CVE-2026-8674glibc@2.39-0ubuntu8.9no fix listed
LowGO-2026-4918stdlib@go1.24.61.25.10
LowGO-2026-4342stdlib@go1.24.61.24.12
LowGO-2026-5026stdlib@go1.24.61.25.13
LowUBUNTU-CVE-2026-86138libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-3832gnutls28@3.8.3-1.1ubuntu3.63.8.3-1.1ubuntu3.6+Fips1.2
LowGO-2025-4009stdlib@go1.24.61.24.8
LowGO-2025-4006stdlib@go1.24.61.24.8
LowGO-2026-4870stdlib@go1.24.61.25.9
LowDEBIAN-CVE-2026-19542glibc@2.36-9+deb12u13no fix listed
LowDEBIAN-CVE-2026-4438glibc@2.36-9+deb12u132.36-9+deb12u14
LowGO-2026-4971stdlib@go1.24.61.25.10
LowGO-2026-4947stdlib@go1.24.61.25.9
LowGO-2026-5037stdlib@go1.24.61.25.11
LowUBUNTU-CVE-2026-75432yaml-cpp@0.8.0+dfsg-6build1no fix listed
LowGO-2026-5972stdlib@go1.24.61.25.13
LowGO-2026-6088stdlib@go1.24.61.25.13
LowGO-2026-6089stdlib@go1.24.61.25.13
LowGO-2026-6090stdlib@go1.24.61.25.13
LowGO-2025-4012stdlib@go1.24.61.24.8
LowGO-2026-5038stdlib@go1.24.61.25.11
LowGO-2025-4011stdlib@go1.24.61.24.8
LowGO-2025-4015stdlib@go1.24.61.24.8
LowGO-2026-6218stdlib@go1.24.61.25.13
LowUBUNTU-CVE-2024-7246grpc@1.51.1-4.1build5no fix listed
LowUBUNTU-CVE-2026-86144libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowGO-2026-6355golang.org/x/crypto@v0.55.00.56.0
LowUBUNTU-CVE-2026-5419gnutls28@3.8.3-1.1ubuntu3.63.8.3-1.1ubuntu3.6+Fips1.2
LowUBUNTU-CVE-2026-86805glibc@2.39-0ubuntu8.9no fix listed
LowGO-2025-4008stdlib@go1.24.61.24.8
LowGO-2025-4010stdlib@go1.24.61.24.8
LowGO-2025-4155stdlib@go1.24.61.24.11
LowGO-2025-4014stdlib@go1.24.61.24.8
LowUBUNTU-CVE-2026-76781libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-54370acl@2.3.2-1build1.1no fix listed
LowGO-2026-6354golang.org/x/crypto@v0.55.00.56.0
LowUBUNTU-CVE-2024-10041pam@1.5.3-5ubuntu5.7no fix listed
LowGO-2026-4976stdlib@go1.24.61.25.10
LowGO-2026-5039stdlib@go1.24.61.25.11
LowGO-2025-4007stdlib@go1.24.61.24.9
LowGO-2026-4980stdlib@go1.24.61.25.10
LowGO-2026-5856stdlib@go1.24.61.25.12
LowGO-2025-4013stdlib@go1.24.61.24.8
LowGO-2026-5841github.com/klauspost/compress@v1.18.01.18.7
LowGO-2026-4946stdlib@go1.24.61.25.9

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.0.0latest—4.0.0020161381,560
3.9.98yesterday3.9.9820161381,560
3.9.712 days ago3.9.7120161351,537
3.9.404 days ago3.9.4020171341,547
3.9.275 days ago3.9.2720181351,577
3.9.186 days ago3.9.1820181351,578
3.8.997 days ago3.8.9920191381,638
3.8.7110 days ago3.8.7120171391,602
3.8.6811 days ago3.8.6820171371,587
3.8.6312 days ago3.8.6320171371,587
3.8.4314 days ago3.8.4320171371,578
3.8.3115 days ago3.8.3120231431,760
3.8.2816 days ago3.8.2820231451,774
3.8.2317 days ago3.8.2320231451,774
3.8.0—3.8.00——
3.7.9219 days ago3.7.9220211401,681
3.7.8620 days ago3.7.8620211401,681
3.7.8421 days ago3.7.8420211401,681
3.7.8122 days ago3.7.8120211501,722
3.7.6923 days ago3.7.6920211491,716
3.7.6623 days ago3.7.6620211491,716
3.7.5725 days ago3.7.57001376876
3.7.5226 days ago3.7.52001376876
3.7.2927 days ago3.7.29001376876

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/magertron/mcp-orchestrator.svg)](https://charts.stackradar.io/charts/magertron/mcp-orchestrator)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 2 Oct 2026 · scanned 2 Oct 2026 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.