standard-application-stack 11.4.1 Helm chart
mintelScored 15 Sept 2026
A generic chart to support most common application requirements
Version 11.4.1 todayApp version not verified against the render 0Artifact Hub
standard-application-stack 11.4.1 deploys 12 container images: docker.elastic.co/kibana/kibana, localstack/localstack, library/docker, mailhog/mailhog and 8 more. Across the 6 measured, 766 findings — 7 critical, 22 high — 4 on CISA KEV. The highest contribution is GHSA-jfh8-c2jp-5v3q in log4j-core 2.13.0, fixed in 2.15.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| docker.elastic.co/ | 7.5.2 | — | unmeasured |
| localstack/ | latest | 0023195 | 2,068 |
| library/ | 20.10-dind | 1938172 | 2,787 |
| mailhog/ | v1.0.1 | 16133 | 778 |
| opensearchproject/ | 1.0.0 | 0452113 | 2,388 |
| k3d-default.localhost:5000/ | v0.0.0 | — | unmeasured |
| docker.elastic.co/ | 7.5.2 | — | unmeasured |
| bitnami/ | 10.6.8-debian-10-r0 | — | unmeasured |
| library/ | latest | 0000 | 0 |
| opensearchproject/ | 1.1.0 | 535176 | 2,494 |
| bitnami/ | 13.5.0-debian-10-r52 | — | unmeasured |
| bitnami/ | 6.2.7-debian-10-r23 | — | unmeasured |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DEBIAN-CVE-2026-6238 | glibc | no fix listed |
| Low | GHSA-w8wr-v893-vjvp | tar | 7.5.18 |
| Low | GO-2023-1705 | stdlib | 1.19.8 |
| Low | GHSA-wf66-mphr-4c4r | kafka-clients | 3.9.2 |
| Low | GO-2023-1878 | stdlib | 1.19.11 |
| Low | ALPINE-CVE-2021-42374 | busybox | 1.31.1-r21 |
| Low | ALPINE-CVE-2023-2975 | openssl | 3.1.1-r2 |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | DEBIAN-CVE-2026-5435 | glibc | no fix listed |
| Low | GHSA-4gc7-5j7h-4qph | spring-context | no fix listed |
| Low | GHSA-c2gf-v879-257j | netty-codec-http2 | 4.1.135.Final |
| Low | GHSA-hpcv-96wg-7vj8 | dompurify | 3.4.6 |
| Low | DEBIAN-CVE-2026-3442 | binutils | no fix listed |
| Low | DEBIAN-CVE-2026-54369 | acl | no fix listed |
| Low | GO-2024-2963 | stdlib | 1.21.12 |
| Low | GO-2023-1702 | stdlib | 1.19.8 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | DEBIAN-CVE-2026-7017 | perl | 5.40.1-6+deb13u1 |
| Low | GHSA-rx8g-88g5-qh64 | min-document | 2.19.1 |
| Low | GHSA-84h7-rjj3-6jx4 | netty-codec-http | 4.1.129.Final |
| Low | DEBIAN-CVE-2026-54371 | attr | no fix listed |
| Low | DEBIAN-CVE-2025-7546 | binutils | no fix listed |
| Low | MAL-2022-4691 | monorepo-symlink-test | no fix listed |
| Low | GHSA-xw73-rw38-6vjc | github.com/ | 24.0.9 |
| Low | DEBIAN-CVE-2025-1176 | binutils | no fix listed |
| Low | GHSA-j5w8-q4qc-rx2x | golang.org/ | 0.45.0 |
| Low | GHSA-r47g-fvhr-h676 | dompurify | 3.4.6 |
| Low | DEBIAN-CVE-2026-6846 | binutils | no fix listed |
| Low | GHSA-hmfx-3pcx-653p | github.com/ | 1.6.18 |
| Low | GO-2023-2375 | stdlib | 1.20.0 |
| Low | DEBIAN-CVE-2025-15079 | curl | no fix listed |
| Low | GHSA-vvgc-356p-c3xw | golang.org/ | 0.38.0 |
| Low | GHSA-65ch-62r8-g69g | node-forge | 1.3.2 |
| Low | GHSA-q7cg-457f-vx79 | joi | 17.13.4 |
| Low | GHSA-crv5-9vww-q3g8 | dompurify | 3.4.0 |
| Low | GHSA-g2j6-57v7-gm8c | github.com/ | 1.1.5 |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | GO-2023-2382 | stdlib | 1.20.12 |
| Low | GHSA-22g5-r2x5-97cx | showdown | no fix listed |
| Low | GHSA-qpw4-5x99-6vjp | golang.org/ | 0.52.0 |
| Low | GHSA-c69g-56f8-xwqj | netty-codec-http2 | 4.1.136.Final |
| Low | GHSA-f6x5-jh6r-wrfv | golang.org/ | 0.45.0 |
| Low | GHSA-gvwx-54wh-qm9j | tar | 7.5.17 |
| Low | GHSA-78mq-xcr3-xm33 | golang.org/ | 0.52.0 |
| Low | GO-2024-2599 | stdlib | 1.21.8 |
| Low | GHSA-cr32-g25g-vxjj | showdown | no fix listed |
| Low | GHSA-6pjf-3r9x-m592 | github.com/ | 3.1.1 |
| Low | GO-2024-3106 | stdlib | 1.22.7 |
| Low | ALPINE-CVE-2023-42364 | busybox | 1.36.1-r7 |
| Low | GHSA-68m8-v89j-7j2p | bc-fips | 1.0.2.4 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 11.4.1latest | today | — | 722177559 | 10,515 |
| 11.4.0 | 1 month ago | — | 722178567 | 10,639 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.