StackRadar

iot Helm chart

mmontesVerified publisher

Scored 14 Sept 2026

General purpose Internet of Things platform

Latest 0.3.2 3 years agoapp version v3.11.0 0Artifact Hub

iot 0.3.2 deploys 7 container images: ghcr.io/mmontes11/iot-back, ghcr.io/mmontes11/iot-biot, ghcr.io/mmontes11/iot-front, ghcr.io/mmontes11/iot-mosquitto and 3 more. Across them, 480 findings6 critical, 48 high. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1k-r0, fixed in 1.1.1l-r0.

Radar Score

10,608648224202

480 findings over 7 of 7 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

7 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/mmontes11/iot-backv3.11.01846542,134
ghcr.io/mmontes11/iot-biotv3.11.01837461,865
ghcr.io/mmontes11/iot-frontv3.11.01832101,450
ghcr.io/mmontes11/iot-mosquittov3.11.00153191
ghcr.io/mmontes11/iot-nginxv3.11.01832101,450
ghcr.io/mmontes11/iot-thingv3.11.01737441,792
ghcr.io/mmontes11/iot-workerv3.11.01835351,726

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

67 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-vcc3-ghjq-m6frdecode-uri-component@0.2.00.5.0
LowGHSA-rhx6-c78j-4q9wpath-to-regexp@0.1.70.1.12
LowGHSA-hj48-42vr-x3v9path-parse@1.0.61.0.7
LowALPINE-CVE-2021-20205libjpeg-turbo@2.0.5-r02.1.0-r0
LowALPINE-CVE-2022-27774curl@7.69.1-r37.79.1-r1
LowALPINE-CVE-2021-22924curl@7.69.1-r37.78.0-r0
LowGHSA-34x7-hfp2-rc4vtar@4.4.137.5.7
LowALPINE-CVE-2021-40528libgcrypt@1.8.5-r01.8.8-r1
LowALPINE-CVE-2021-22923curl@7.69.1-r37.78.0-r0
LowGHSA-25hc-qcg6-38wjsocket.io@2.5.02.5.1
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.111.1.18
LowGHSA-f5x3-32g6-xq36tar@4.4.136.2.1
LowGHSA-8cf7-32gw-wr33jsonwebtoken@8.5.19.0.0
LowGHSA-qffp-2rhf-9h96tar@4.4.137.5.10
LowALPINE-CVE-2023-0465openssl@1.1.1t-r01.1.1t-r2
LowGHSA-23hp-3jrh-7fpwtar@4.4.137.5.19
LowGHSA-hmw2-7cc7-3qxxform-data@2.3.22.5.6
LowGHSA-7r86-cg39-jmmjminimatch@3.0.43.1.3
LowGHSA-2m8v-j782-fhvrsocket.io-parser@3.3.33.3.6
LowGHSA-8qq5-rm4j-mr97tar@4.4.137.5.3
LowGHSA-776f-qx25-q3ccxml2js@0.4.00.5.0
LowGHSA-23c5-xmqv-rm74minimatch@3.0.43.1.4
LowALPINE-CVE-2020-8284curl@7.69.1-r37.74.0-r0
LowGHSA-qpx9-hpmf-5gmwunderscore@1.13.61.13.8
LowGHSA-mh99-v99m-4gvgbrace-expansion@1.1.111.1.17
LowGHSA-8x88-c5mf-7j5wtar@4.4.137.5.18
LowGHSA-rv95-896h-c2vcexpress@4.18.24.19.2
LowGHSA-6fx8-h7jm-663jparseuri@0.0.6no fix listed
LowGHSA-2g4f-4pwh-qvx6ajv@6.12.66.14.0
LowGHSA-p8p7-x288-28g6request@2.88.0no fix listed
LowGHSA-r6q2-hw4h-h46wtar@4.4.137.5.4
LowGHSA-r292-9mhp-454mtar@4.4.137.5.21
LowALPINE-CVE-2021-22890curl@7.69.1-r37.76.0-r0
LowALPINE-CVE-2021-23839openssl@1.1.1i-r01.1.1j-r0
LowGHSA-w5hq-g745-h8pquuid@3.3.311.1.1
LowGHSA-gxpj-cx7g-858cdebug@4.1.14.3.1
LowGHSA-9ppj-qmqm-q256tar@4.4.137.5.11
LowGHSA-qwph-4952-7xr6jsonwebtoken@8.5.19.0.0
LowGHSA-mpwj-fcr6-x34cyarn@1.22.51.22.13
LowALPINE-CVE-2021-22898curl@7.69.1-r37.77.0-r0
LowALPINE-CVE-2025-26519musl@1.2.3-r21.2.3-r4
LowGHSA-f886-m6hf-6m8vbrace-expansion@1.1.111.1.13
LowGHSA-wpg9-53fq-2r8hmongoose@5.13.166.13.9
LowGHSA-83g3-92jg-28cxtar@4.4.137.5.8
LowGHSA-664h-wqgq-64gwmongoose@5.13.166.13.10
LowGHSA-w8wr-v893-vjvptar@4.4.137.5.18
LowGHSA-hjrf-2m68-5959jsonwebtoken@8.5.19.0.0
LowALPINE-CVE-2021-42374busybox@1.31.1-r191.31.1-r21
LowGHSA-869p-cjfg-cm3xjws@3.2.23.2.3
LowMAL-2022-4933npm-cli-docs@0.1.0no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.3.2latest3 years agov3.11.064822420210,608

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/mmontes/iot.svg)](https://charts.stackradar.io/charts/mmontes/iot)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.