StackRadar

mlflow-server Helm chart

mlflowserver

Scored 14 Sept 2026

A Helm chart for MLFlow On Kubernetes

Latest 0.1.9 3 years agoapp version 2.1.1 1Artifact Hub

mlflow-server 0.1.9 deploys 3 container images: jwilder/dockerize, buntha/mlflow and bitnami/postgresql. Across the 2 measured, 396 findings7 critical, 11 high 8 on CISA KEV. The highest contribution is GHSA-7gwp-5pfp-969j in mlflow 2.1.1, fixed in 3.15.0.

Radar Score

5,80471199279

396 findings over 2 of 3 images measured

KEV ×8 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
jwilder/dockerizelatest00554502
buntha/mlflow2.1.1711942255,302
bitnami/postgresql14.5.0-debian-11-r21unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

279 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-7545-fcxq-7j24gitpython@3.1.293.1.48
LowGHSA-2mqj-m65w-jghxgitpython@3.1.293.1.41
LowDSA-5484-1librsvg@2.50.3+dfsg-12.50.3+dfsg-1+deb11u1
LowPYSEC-2024-161pyarrow@10.0.117.0.0
LowGHSA-m4p7-r5rc-7g4jpyasn1@0.4.80.6.4
LowDLA-4251-1libxml2@2.9.10+dfsg-6.7+deb11u32.9.10+dfsg-6.7+deb11u8
LowDLA-3879-1bluez@5.55-3.15.55-3.1+deb11u2
LowGHSA-9hjg-9r4m-mvj7requests@2.28.12.32.4
LowGHSA-8qvm-5x2c-j2w7protobuf@4.21.124.25.8
LowDSA-5650-1util-linux@2.36.1-8+deb11u12.36.1-8+deb11u2
LowDSA-5490-1aom@1.0.0.errata1-31.0.0.errata1-3+deb11u1
LowGHSA-8ppf-4f7h-5ppjpyasn1@0.4.80.6.4
LowGHSA-hm4w-wwcw-mr6rpyasn1@0.4.80.6.4
LowGHSA-h5c8-rqwp-cp95jinja2@3.1.23.1.3
LowDLA-4026-1tiff@4.2.0-1+deb11u14.2.0-1+deb11u6
LowGHSA-29vq-49wr-vm6xwerkzeug@2.2.23.1.6
LowGHSA-768j-98cg-p3fvfonttools@4.38.04.60.2
LowGO-2026-4341stdlib@go1.25.51.24.12
LowDSA-5346-1libde265@1.0.8-11.0.11-0+deb11u1
LowGHSA-hgf8-39gv-g3f2werkzeug@2.2.23.1.4
LowDLA-4127-1subversion@1.14.1-3+deb11u11.14.1-3+deb11u2
LowGHSA-w5xq-c4pf-ghq7mlflow@2.1.13.10.0
LowDSA-5726-1krb5@1.18.3-6+deb11u31.18.3-6+deb11u5
LowGHSA-prg7-hcfm-mfcrsqlparse@0.4.30.6.0
LowDSA-5686-1dav1d@0.7.1-30.7.1-3+deb11u1
LowDLA-3893-1expat@2.2.10-2+deb11u52.2.10-2+deb11u6
LowGHSA-rwj8-pgh3-r573gitpython@3.1.293.1.52
LowDSA-5622-1postgresql-13@13.9-0+deb11u113.14-0+deb11u1
LowGHSA-752w-5fwx-jx9fpyjwt@2.6.02.12.0
LowGHSA-v87r-6q3f-2j67gitpython@3.1.293.1.49
LowGHSA-pgqp-8h46-6x4jmlflow@2.1.13.5.0
LowDSA-5333-1tiff@4.2.0-1+deb11u14.2.0-1+deb11u3
LowDSA-5365-1curl@7.74.0-1.3+deb11u37.74.0-1.3+deb11u7
LowGHSA-mv93-w799-cj2wgitpython@3.1.293.1.50
LowDSA-5587-1curl@7.74.0-1.3+deb11u37.74.0-1.3+deb11u11
LowDSA-5433-1libx11@2:1.7.2-12:1.7.2-1+deb11u1
LowPYSEC-2026-3948gitpython@3.1.293.1.57
LowGHSA-65h7-c7c4-mghxmlflow@2.1.13.9.0
LowDSA-5746-1postgresql-13@13.9-0+deb11u113.16-0+deb11u1
LowDLA-4107-1openjpeg2@2.4.0-32.4.0-3+deb11u1
LowDLA-4321-1openssl@1.1.1n-0+deb11u31.1.1w-0+deb11u4
LowDSA-5305-1libksba@1.5.0-3+deb11u11.5.0-3+deb11u2
LowDLA-3926-1perl@5.32.1-4+deb11u25.32.1-4+deb11u4
LowGHSA-hh9p-6wh2-4mfcgitpython@3.1.293.1.58
LowGHSA-3rp5-jjmw-4wv2gitpython@3.1.293.1.53
LowGHSA-34jh-p97f-mpxfurllib3@1.26.131.26.19
LowGHSA-4xh5-x5gv-qwphpip@22.0.425.3
LowGHSA-q3gw-8236-5jw4mlflow@2.1.1no fix listed
LowDSA-5370-1apr@1.7.0-6+deb11u11.7.0-6+deb11u2
LowGHSA-45gg-vh54-h5m9golang.org/x/crypto@v0.45.00.52.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.1.9latest3 years ago2.1.1711992795,804

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/mlflowserver/mlflow-server.svg)](https://charts.stackradar.io/charts/mlflowserver/mlflow-server)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.