StackRadar

standard-application-stack 11.4.0 Helm chart

mintel

Scored 14 Sept 2026

A generic chart to support most common application requirements

Version 11.4.0 1 month agoApp version not verified against the render 0Artifact Hub

standard-application-stack 11.4.0 deploys 12 container images: docker.elastic.co/kibana/kibana, localstack/localstack, library/docker, mailhog/mailhog and 8 more. Across the 6 measured, 770 findings7 critical, 22 high 4 on CISA KEV. The highest contribution is GHSA-jfh8-c2jp-5v3q in log4j-core 2.13.0, fixed in 2.15.0.

Radar Score

10,603722178562

770 findings over 6 of 12 images measured

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

12 images
ImageTagVulnerabilitiesRadar Score
docker.elastic.co/kibana/kibana7.5.2unmeasured
localstack/localstacklatest00241982,156
library/docker20.10-dind19381722,787
mailhog/mailhogv1.0.116133778
opensearchproject/opensearch-dashboards1.0.004521132,388
k3d-default.localhost:5000/testv0.0.0unmeasured
docker.elastic.co/elasticsearch/elasticsearch×27.5.2unmeasured
bitnami/mariadb10.6.8-debian-10-r0unmeasured
library/busyboxlatest00000
opensearchproject/opensearch1.1.05351762,494
bitnami/postgresql13.5.0-debian-10-r52unmeasured
bitnami/redis×26.2.7-debian-10-r23unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

766 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2025-66864binutils@2.44-3no fix listed
LowGHSA-m4cv-j2px-7723netty-codec-http@4.1.45.Final4.1.133.Final
LowDEBIAN-CVE-2025-1147binutils@2.44-3no fix listed
LowGO-2023-1752stdlib@go1.19.71.19.9
LowDEBIAN-CVE-2026-6238glibc@2.41-12+deb13u3no fix listed
LowGHSA-w8wr-v893-vjvptar@4.4.137.5.18
LowGO-2023-1705stdlib@go1.19.71.19.8
LowGHSA-wf66-mphr-4c4rkafka-clients@2.5.03.9.2
LowGO-2023-1878stdlib@go1.19.71.19.11
LowALPINE-CVE-2021-42374busybox@1.31.1-r161.31.1-r21
LowALPINE-CVE-2023-2975openssl@3.1.0-r43.1.1-r2
LowGHSA-45gg-vh54-h5m9golang.org/x/crypto@v0.2.00.52.0
LowDEBIAN-CVE-2026-5435glibc@2.41-12+deb13u3no fix listed
LowGHSA-4gc7-5j7h-4qphspring-context@5.2.5.RELEASEno fix listed
LowGHSA-c2gf-v879-257jnetty-codec-http2@4.1.45.Final4.1.135.Final
LowGHSA-hpcv-96wg-7vj8dompurify@2.1.13.4.6
LowDEBIAN-CVE-2026-3442binutils@2.44-3no fix listed
LowDEBIAN-CVE-2026-54369acl@2.3.2-2+b1no fix listed
LowGO-2024-2963stdlib@go1.19.71.21.12
LowGO-2023-1702stdlib@go1.19.71.19.8
LowGHSA-5cv4-jp36-h3mwgolang.org/x/net@v0.4.00.55.0
LowDEBIAN-CVE-2026-7017perl@5.40.1-65.40.1-6+deb13u1
LowGHSA-rx8g-88g5-qh64min-document@2.19.02.19.1
LowGHSA-84h7-rjj3-6jx4netty-codec-http@4.1.45.Final4.1.129.Final
LowDEBIAN-CVE-2026-54371attr@1:2.5.2-3no fix listed
LowDEBIAN-CVE-2025-7546binutils@2.44-3no fix listed
LowMAL-2022-4691monorepo-symlink-test@0.0.0no fix listed
LowGHSA-xw73-rw38-6vjcgithub.com/docker/docker@v23.0.0-rc.1+incompatible24.0.9
LowDEBIAN-CVE-2025-1176binutils@2.44-3no fix listed
LowGHSA-j5w8-q4qc-rx2xgolang.org/x/crypto@v0.2.00.45.0
LowGHSA-r47g-fvhr-h676dompurify@2.1.13.4.6
LowDEBIAN-CVE-2026-6846binutils@2.44-3no fix listed
LowGHSA-hmfx-3pcx-653pgithub.com/containerd/containerd@v1.6.16-0.20230124210447-1709cfe273d91.6.18
LowGO-2023-2375stdlib@go1.19.71.20.0
LowDEBIAN-CVE-2025-15079curl@8.14.1-2+deb13u4no fix listed
LowGHSA-vvgc-356p-c3xwgolang.org/x/net@v0.4.00.38.0
LowGHSA-65ch-62r8-g69gnode-forge@0.10.01.3.2
LowGHSA-q7cg-457f-vx79joi@13.7.017.13.4
LowGHSA-crv5-9vww-q3g8dompurify@2.1.13.4.0
LowGHSA-g2j6-57v7-gm8cgithub.com/opencontainers/runc@v1.1.31.1.5
LowGHSA-qc2q-p7wx-3px3google.golang.org/grpc@v1.50.11.83.1
LowGO-2023-2382stdlib@go1.19.71.20.12
LowGHSA-22g5-r2x5-97cxshowdown@1.9.1no fix listed
LowGHSA-qpw4-5x99-6vjpgolang.org/x/crypto@v0.2.00.52.0
LowGHSA-c69g-56f8-xwqjnetty-codec-http2@4.1.45.Final4.1.136.Final
LowGHSA-f6x5-jh6r-wrfvgolang.org/x/crypto@v0.2.00.45.0
LowGHSA-gvwx-54wh-qm9jtar@4.4.137.5.17
LowGHSA-78mq-xcr3-xm33golang.org/x/crypto@v0.2.00.52.0
LowGO-2024-2599stdlib@go1.19.71.21.8
LowGHSA-cr32-g25g-vxjjshowdown@1.9.1no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
11.4.0latest1 month ago72217856210,603

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/mintel/standard-application-stack.svg)](https://charts.stackradar.io/charts/mintel/standard-application-stack)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.