StackRadar

mcp-orchestrator 4.0.13 Helm chart

magertronVerified publisher

Scored 3 Oct 2026

MCP Orchestrator — Kubernetes-native control plane for managing MCP servers

Version 4.0.13 todayapp version 4.0.13 1Artifact Hub

mcp-orchestrator 4.0.13 deploys 7 container images: curtismager20/mcp-orchestrator, curtismager20/mcp-sync, curtismager20/mcp-chat-daemon, envoyproxy/envoy and 3 more. Across them, 156 findings — 2 critical, 0 high. The highest contribution is UBUNTU-CVE-2019-9515 in grpc 1.51.1-4.1build5, with no fix listed.

Radar Score

1,7982021133

156 findings over 7 of 7 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

7 images
ImageTagVulnerabilitiesRadar Score
curtismager20/mcp-orchestrator4.0.1320866842
curtismager20/mcp-sync4.0.13001017
curtismager20/mcp-chat-daemon4.0.1300000
envoyproxy/envoydistroless-v1.33.1400722362
library/busybox1.3600000
curtismager20/mcp-inventory4.0.13000441
library/postgres×217-alpine00541536

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

150 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2026-86143libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowGO-2026-4976stdlib@go1.24.61.25.10
LowGO-2026-5039stdlib@go1.24.61.25.11
LowUBUNTU-CVE-2026-41989libgcrypt20@1.10.3-2ubuntu0.21.12.0-2ubuntu0.1~Fips1~rc11
LowUBUNTU-CVE-2026-42014gnutls28@3.8.3-1.1ubuntu3.63.8.3-1.1ubuntu3.6+Fips1.2
LowGO-2026-5856stdlib@go1.24.61.25.12
LowUBUNTU-CVE-2026-54369acl@2.3.2-1build1.1no fix listed
LowUBUNTU-CVE-2026-86139libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-78409util-linux@2.39.3-9ubuntu6.6no fix listed
LowUBUNTU-CVE-2026-86142libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-89157pcre2@10.42-4ubuntu2.1no fix listed
LowUBUNTU-CVE-2026-89161pcre2@10.42-4ubuntu2.1no fix listed
LowUBUNTU-CVE-2026-8674glibc@2.39-0ubuntu8.9no fix listed
LowDEBIAN-CVE-2026-4438glibc@2.36-9+deb12u132.36-9+deb12u14
LowGO-2026-4340stdlib@go1.24.61.24.12
LowUBUNTU-CVE-2026-86138libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-3832gnutls28@3.8.3-1.1ubuntu3.63.8.3-1.1ubuntu3.6+Fips1.2
LowDEBIAN-CVE-2026-19542glibc@2.36-9+deb12u13no fix listed
LowUBUNTU-CVE-2026-75432yaml-cpp@0.8.0+dfsg-6build1no fix listed
LowUBUNTU-CVE-2024-7246grpc@1.51.1-4.1build5no fix listed
LowUBUNTU-CVE-2026-86144libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-5419gnutls28@3.8.3-1.1ubuntu3.63.8.3-1.1ubuntu3.6+Fips1.2
LowUBUNTU-CVE-2026-86805glibc@2.39-0ubuntu8.9no fix listed
LowGO-2026-4869stdlib@go1.24.61.25.9
LowUBUNTU-CVE-2026-76781libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-54370acl@2.3.2-1build1.1no fix listed
LowUBUNTU-CVE-2024-10041pam@1.5.3-5ubuntu5.7no fix listed
LowUBUNTU-CVE-2026-102473dash@0.5.12-6ubuntu5no fix listed
LowDEBIAN-CVE-2010-4756glibc@2.36-9+deb12u13no fix listed
LowUBUNTU-CVE-2024-56433shadow@1:4.13+dfsg1-4ubuntu3.2no fix listed
LowUBUNTU-CVE-2026-89092glibc@2.39-0ubuntu8.9no fix listed
LowUBUNTU-CVE-2026-18374glibc@2.39-0ubuntu8.9no fix listed
LowUBUNTU-CVE-2026-97399glibc@2.39-0ubuntu8.9no fix listed
LowUBUNTU-CVE-2026-89160pcre2@10.42-4ubuntu2.1no fix listed
LowUBUNTU-CVE-2026-18508tar@1.35+dfsg-3ubuntu0.4no fix listed
LowUBUNTU-CVE-2026-41990libgcrypt20@1.10.3-2ubuntu0.21.12.0-2ubuntu0.1~Fips1~rc11
LowUBUNTU-CVE-2022-3219gnupg2@2.4.4-2ubuntu17.6no fix listed
LowUBUNTU-CVE-2026-102474dash@0.5.12-6ubuntu5no fix listed
LowUBUNTU-CVE-2025-6140spdlog@1:1.12.0+ds-2build1no fix listed
LowUBUNTU-CVE-2026-89156pcre2@10.42-4ubuntu2.1no fix listed
LowUBUNTU-CVE-2026-18477tar@1.35+dfsg-3ubuntu0.4no fix listed
LowGO-2026-5932golang.org/x/crypto@v0.55.0no fix listed
LowUBUNTU-CVE-2026-95818glibc@2.39-0ubuntu8.9no fix listed
LowGO-2026-5024golang.org/x/sys@v0.1.00.44.0
LowUBUNTU-CVE-2026-86137libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-86141libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-89162pcre2@10.42-4ubuntu2.1no fix listed
LowUBUNTU-CVE-2026-40228systemd@255.4-1ubuntu8.17no fix listed
LowGO-2026-4602stdlib@go1.24.61.25.8
LowDEBIAN-CVE-2026-6368glibc@2.36-9+deb12u13no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.0.13latesttoday4.0.1320211331,798
4.0.0—4.0.0020211331,781
3.9.982 days ago3.9.9820211331,781
3.9.713 days ago3.9.7120211301,758
3.9.405 days ago3.9.4020221291,768
3.9.276 days ago3.9.2720231301,798
3.9.187 days ago3.9.1820231301,799
3.8.998 days ago3.8.9920241331,859
3.8.7111 days ago3.8.7120221341,823
3.8.6812 days ago3.8.6820221321,808
3.8.6313 days ago3.8.6320221321,808
3.8.4315 days ago3.8.4320221321,799
3.8.3116 days ago3.8.3120231431,759
3.8.2817 days ago3.8.2820231451,773
3.8.2318 days ago3.8.2320231451,773
3.8.0—3.8.00——
3.7.9220 days ago3.7.9220211401,680
3.7.8621 days ago3.7.8620211401,680
3.7.8422 days ago3.7.8420211401,680
3.7.8123 days ago3.7.8120211501,721
3.7.6924 days ago3.7.6920211491,715
3.7.6624 days ago3.7.6620211491,715
3.7.5726 days ago3.7.57001376875
3.7.5227 days ago3.7.52001376875
3.7.2928 days ago3.7.29001376875

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/magertron/mcp-orchestrator.svg)](https://charts.stackradar.io/charts/magertron/mcp-orchestrator)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 3 Oct 2026 · scanned 3 Oct 2026 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.