standard-application-stack 11.4.1 Helm chart
mintelScored 15 Sept 2026
A generic chart to support most common application requirements
Version 11.4.1 todayApp version not verified against the render 0Artifact Hub
standard-application-stack 11.4.1 deploys 12 container images: docker.elastic.co/kibana/kibana, localstack/localstack, library/docker, mailhog/mailhog and 8 more. Across the 6 measured, 766 findings — 7 critical, 22 high — 4 on CISA KEV. The highest contribution is GHSA-jfh8-c2jp-5v3q in log4j-core 2.13.0, fixed in 2.15.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| docker.elastic.co/ | 7.5.2 | — | unmeasured |
| localstack/ | latest | 0023195 | 2,068 |
| library/ | 20.10-dind | 1938172 | 2,787 |
| mailhog/ | v1.0.1 | 16133 | 778 |
| opensearchproject/ | 1.0.0 | 0452113 | 2,388 |
| k3d-default.localhost:5000/ | v0.0.0 | — | unmeasured |
| docker.elastic.co/ | 7.5.2 | — | unmeasured |
| bitnami/ | 10.6.8-debian-10-r0 | — | unmeasured |
| library/ | latest | 0000 | 0 |
| opensearchproject/ | 1.1.0 | 535176 | 2,494 |
| bitnami/ | 13.5.0-debian-10-r52 | — | unmeasured |
| bitnami/ | 6.2.7-debian-10-r23 | — | unmeasured |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | ALPINE-CVE-2023-6129 | openssl | 3.1.4-r3 |
| Medium | GHSA-3949-f494-cm99 | prismjs | 1.27.0 |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang | no fix listed |
| Medium | GHSA-j288-q9x7-2f5v | commons-lang3 | 3.18.0 |
| Medium | GHSA-grv7-fg5c-xmjg | braces | 3.0.3 |
| Medium | GHSA-4jq9-2xhw-jpx7 | json | 20231013 |
| Medium | GHSA-jf5r-8hm2-f872 | url-parse | 1.5.9 |
| Medium | DEBIAN-CVE-2011-3389 | gnutls28 | no fix listed |
| Medium | GO-2026-4887 | github.com/ | no fix listed |
| Medium | GHSA-rcjv-mgp8-qvmr | go.opentelemetry.io/ | 0.44.0 |
| Medium | GHSA-rcjv-mgp8-qvmr | go.opentelemetry.io/ | 0.44.0 |
| Medium | GHSA-3h5v-q93c-6h6q | ws | 7.5.10 |
| Medium | GHSA-c4r9-r8fh-9vj2 | snakeyaml | 1.31 |
| Medium | GHSA-78wr-2p64-hpwj | commons-io | 2.14.0 |
| Medium | GHSA-c429-5p7v-vgjp | hoek | no fix listed |
| Medium | GHSA-3qp7-7mw8-wx86 | netty-handler | 4.1.135.Final |
| Medium | GHSA-8r3f-844c-mc37 | google.golang.org/ | 1.33.0 |
| Medium | ALPINE-CVE-2024-0727 | openssl | 3.1.4-r5 |
| Medium | GHSA-m3r6-h7wv-7xxv | github.com/ | 0.12.5 |
| Medium | GHSA-98wm-3w3q-mw94 | snakeyaml | 1.31 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | GHSA-3w37-5p3p-jv92 | cxf-core | 3.4.10 |
| Medium | GHSA-3vqj-43w4-2q58 | json | 20230227 |
| Medium | DEBIAN-CVE-2019-1010024 | glibc | no fix listed |
| Medium | GHSA-3x8x-79m2-3w2w | jackson-databind | 2.12.6 |
| Medium | GHSA-rmj7-2vxq-3g9f | jackson-databind | 2.18.8 |
| Medium | GHSA-wxqc-pxw9-g2p8 | spring-expression | 5.2.24.RELEASE |
| Medium | ALPINE-CVE-2023-6237 | openssl | 3.1.4-r4 |
| Medium | DEBIAN-CVE-2026-5450 | glibc | 2.41-12+deb13u4 |
| Medium | GHSA-493p-pfq6-5258 | json-smart | 2.4.9 |
| Medium | GHSA-5gfm-wpxj-wjgq | node-forge | 1.3.2 |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | GHSA-x4jg-mjrx-434g | node-forge | 1.3.0 |
| Medium | ALPINE-CVE-2024-9143 | openssl | 3.1.7-r1 |
| Medium | GHSA-j3rv-43j4-c7qm | jackson-databind | 2.18.8 |
| Medium | DEBIAN-CVE-2025-47268 | iputils | no fix listed |
| Medium | ALPINE-CVE-2023-3817 | openssl | 3.1.2-r0 |
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-f23m-r3pf-42rh | lodash-es | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash-es | 4.17.23 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | GHSA-prj3-ccx8-p6x4 | netty-codec-http2 | 4.1.124.Final |
| Medium | GHSA-h46c-h94j-95f3 | jackson-core | 2.15.0 |
| Medium | GHSA-pc3f-x583-g7j2 | github.com/ | 0.5.1 |
| Medium | ALPINE-CVE-2025-31115 | xz | 5.4.3-r1 |
| Medium | GHSA-w37g-rhq8-7m4j | snakeyaml | 1.32 |
| Medium | GHSA-5mcr-gq6c-3hq2 | netty-codec-http | 4.1.59.Final |
| Medium | DEBIAN-CVE-2026-8924 | curl | no fix listed |
| Medium | GHSA-8v38-pw62-9cw2 | url-parse | 1.5.7 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 11.4.1latest | today | — | 722177559 | 10,515 |
| 11.4.0 | 1 month ago | — | 722178567 | 10,639 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.