StackRadar

chatwoot 1.1.201 Helm chart

maxcrm-chartsVerified publisher

Scored 14 Sept 2026

Open-source customer engagement suite, an alternative to Intercom, Zendesk, Salesforce Service Cloud etc. 🔥💬

Version 1.1.201 2 years agoapp version v3.1.0 1Artifact Hub

chatwoot 1.1.201 deploys 4 container images: chatwoot/chatwoot, bitnami/postgresql, bitnami/redis and library/busybox. Across the 2 measured, 400 findings4 critical, 10 high 1 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 8.2.1-r0, fixed in 8.4.0-r0.

Radar Score

5,940410122263

400 findings over 2 of 4 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

4 images
ImageTagVulnerabilitiesRadar Score
chatwoot/chatwoot×4v3.1.04101222635,940
bitnami/postgresql14.4.0-debian-11-r0unmeasured
bitnami/redis×26.2.7-debian-11-r3unmeasured
library/busybox1.2800000

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

400 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumALPINE-CVE-2023-7104sqlite@3.41.2-r23.41.2-r3
MediumGHSA-7wqh-767x-r66vrack@2.2.82.2.13
MediumALPINE-CVE-2023-6237openssl@3.1.2-r03.1.4-r4
MediumGHSA-5gfm-wpxj-wjgqnode-forge@0.10.01.3.2
MediumGHSA-x4jg-mjrx-434gnode-forge@0.10.01.3.0
MediumALPINE-CVE-2024-9143openssl@3.1.2-r03.1.7-r1
MediumALPINE-CVE-2023-46218curl@8.2.1-r08.5.0-r0
MediumGHSA-9xrj-h377-fr87activestorage@7.0.87.2.3.1
MediumALPINE-CVE-2024-4032python3@3.11.5-r03.11.10-r0
MediumGHSA-f23m-r3pf-42rhlodash@4.17.214.18.0
MediumGHSA-xxjr-mmjv-4gpglodash@4.17.214.17.23
MediumALPINE-CVE-2025-0665curl@8.2.1-r08.12.0-r0
MediumGHSA-c7qv-q95q-8v27http-proxy-middleware@0.19.12.0.7
MediumALPINE-CVE-2025-31115xz@5.4.3-r05.4.3-r1
MediumALPINE-CVE-2024-2379curl@8.2.1-r08.7.1-r0
MediumGHSA-73f9-jhhh-hr5mactivestorage@7.0.87.2.3.1
MediumGHSA-8v38-pw62-9cw2url-parse@1.5.11.5.7
MediumGHSA-6fc8-4gx4-v693ws@6.2.16.2.2
MediumGHSA-67hx-6x53-jw92@babel/traverse@7.14.07.23.2
MediumGHSA-hh27-ffr2-f2jcurl-parse@1.5.11.5.2
MediumGHSA-2j26-frm8-cmj9activesupport@7.0.87.2.3.1
MediumGHSA-r46p-8f7g-vvvgactivestorage@7.0.87.2.3.1
MediumGHSA-37ch-88jc-xwx2path-to-regexp@0.1.70.1.13
MediumGHSA-9wv6-86v2-598jpath-to-regexp@0.1.70.1.10
MediumGHSA-p543-xpfm-54cprack@2.2.82.2.19
MediumGHSA-wpv5-97wm-hp9crack@2.2.82.2.19
MediumALPINE-CVE-2025-0938python3@3.11.5-r03.11.12-r0
MediumGHSA-cpq7-6gpm-g9rccipher-base@1.0.41.0.5
MediumALPINE-CVE-2023-27043python3@3.11.5-r03.11.10-r0
MediumGHSA-566m-qj78-rww5postcss@7.0.357.0.36
MediumGHSA-3xgq-45jj-v275cross-spawn@6.0.56.0.6
MediumALPINE-CVE-2024-32021git@2.40.1-r02.40.3-r0
MediumGHSA-qwcr-r2fm-qrc7body-parser@1.19.01.20.3
MediumGHSA-96hv-2xvq-fx4pws@6.2.16.2.4
MediumGHSA-3ppc-4f35-3m26minimatch@3.0.43.1.3
MediumGHSA-25h7-pfq9-p65fflatted@2.0.23.4.0
LowGHSA-vcc3-ghjq-m6frdecode-uri-component@0.2.00.5.0
LowGHSA-rhx6-c78j-4q9wpath-to-regexp@0.1.70.1.12
LowGHSA-hj48-42vr-x3v9path-parse@1.0.61.0.7
LowGHSA-cfm4-qjh2-4765node-forge@0.10.01.3.0
LowGHSA-7g2v-jj9q-g3rgrack@2.2.82.2.11
LowGHSA-v62p-rq8g-8h59pbkdf2@3.1.23.1.3
LowALPINE-CVE-2025-0840binutils@2.40-r72.40-r8
LowALPINE-CVE-2023-38546curl@8.2.1-r08.4.0-r0
LowGHSA-h7cp-r72f-jxh6pbkdf2@3.1.23.1.3
LowALPINE-CVE-2024-9287python3@3.11.5-r03.11.11-r0
LowGHSA-vg3r-rm7w-2xghrexml@3.2.53.2.7
LowGHSA-34x7-hfp2-rc4vtar@2.2.27.5.7
LowGHSA-cxjh-pqwp-8mfpfollow-redirects@1.14.01.15.6
LowGHSA-h8w8-99g7-qmvjconcurrent-ruby@1.2.21.3.7

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.1.201latest2 years agov3.1.04101222635,940

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/maxcrm-charts/chatwoot.svg)](https://charts.stackradar.io/charts/maxcrm-charts/chatwoot)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.