paperless-ngx 7.6.14 Helm chart
mt190502Scored 14 Sept 2026
A community-supported supercharged version of paperless; scan, index and archive all your physical documents
Version 7.6.14 5 months agoapp version 2.20.13 0Artifact Hub
paperless-ngx 7.6.14 deploys 4 container images: library/busybox, ghcr.io/paperless-ngx/paperless-ngx, library/redis and library/postgres. Across them, 1,192 findings — 0 critical, 3 high. The highest contribution is GHSA-frmv-pr5f-9mcr in django 5.2.7, fixed in 5.2.8.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | latest | 0000 | 0 |
| ghcr.io/ | 2.20.13 | 03126776 | 9,275 |
| library/ | 7 | 001493 | 1,049 |
| library/ | 18 | 0019159 | 1,626 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DEBIAN-CVE-2026-5928 | glibc | 2.41-12+deb13u4 |
| Low | PYSEC-2026-3728 | nltk | 3.10.0 |
| Low | GHSA-3gq4-3j92-5w49 | nltk | 3.10.3 |
| Low | DEBIAN-CVE-2026-34872 | mbedtls | 3.6.6-0.1~deb13u1 |
| Low | DEBIAN-CVE-2026-41254 | lcms2 | 2.16-2+deb13u2 |
| Low | DEBIAN-CVE-2023-39329 | openjpeg2 | no fix listed |
| Low | DEBIAN-CVE-2026-6478 | postgresql-17 | 17.10-0+deb13u1 |
| Low | DEBIAN-CVE-2026-7598 | libssh2 | 1.11.1-1+deb13u1 |
| Low | DEBIAN-CVE-2026-6791 | glibc | no fix listed |
| Low | DEBIAN-CVE-2022-27943 | gcc-12 | no fix listed |
| Low | PYSEC-2026-50 | django | 5.2.14 |
| Low | DEBIAN-CVE-2026-56372 | imagemagick | 8:7.1.1.43+dfsg1-1+deb13u12 |
| Low | DEBIAN-CVE-2026-8458 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-53461 | imagemagick | 8:7.1.1.43+dfsg1-1+deb13u10 |
| Low | PYSEC-2026-3740 | nltk | 3.10.3 |
| Low | DEBIAN-CVE-2026-6253 | curl | 8.14.1-2+deb13u4 |
| Low | GHSA-mpf4-983q-p7j4 | tornado | 6.5.8 |
| Low | DEBIAN-CVE-2026-33164 | libde265 | 1.0.15-1+deb13u2 |
| Low | DEBIAN-CVE-2022-24106 | poppler | no fix listed |
| Low | DEBIAN-CVE-2026-49218 | imagemagick | 8:7.1.1.43+dfsg1-1+deb13u10 |
| Low | DEBIAN-CVE-2026-53460 | imagemagick | 8:7.1.1.43+dfsg1-1+deb13u10 |
| Low | DEBIAN-CVE-2026-59850 | libssh | 0.11.5-0+deb13u1 |
| Low | DEBIAN-CVE-2026-66039 | ffmpeg | no fix listed |
| Low | GHSA-w3v8-gmh9-3wv7 | nltk | 3.10.3 |
| Low | DEBIAN-CVE-2025-70103 | jpeg-xl | 0.11.2-0.1~deb13u2 |
| Low | DEBIAN-CVE-2026-30997 | ffmpeg | 7:7.1.5-0+deb13u1 |
| Low | DEBIAN-CVE-2026-45382 | libde265 | 1.0.15-1+deb13u1 |
| Low | DEBIAN-CVE-2026-59847 | libssh | 0.11.5-0+deb13u1 |
| Low | DEBIAN-CVE-2026-45383 | libde265 | 1.0.15-1+deb13u1 |
| Low | DEBIAN-CVE-2025-61915 | cups | no fix listed |
| Low | DEBIAN-CVE-2026-38347 | ffmpeg | 7:7.1.5-0+deb13u1 |
| Low | DEBIAN-CVE-2026-16554 | cjson | no fix listed |
| Low | GHSA-f83h-ghpp-7wcc | pdfminer-six | 20251230 |
| Low | DEBIAN-CVE-2026-4437 | glibc | 2.41-12+deb13u3 |
| Low | DEBIAN-CVE-2026-38344 | ffmpeg | 7:7.1.4-0+deb13u1 |
| Low | DEBIAN-CVE-2026-38346 | ffmpeg | 7:7.1.4-0+deb13u1 |
| Low | DEBIAN-CVE-2026-38348 | ffmpeg | 7:7.1.4-0+deb13u1 |
| Low | DEBIAN-CVE-2026-38349 | ffmpeg | 7:7.1.4-0+deb13u1 |
| Low | DEBIAN-CVE-2026-38350 | ffmpeg | no fix listed |
| Low | GHSA-vfmq-68hx-4jfw | lxml | 6.1.0 |
| Low | GHSA-vrg7-482j-p6f6 | granian | 2.7.4 |
| Low | DEBIAN-CVE-2026-61861 | imagemagick | 8:7.1.1.43+dfsg1-1+deb13u12 |
| Low | GO-2026-4341 | stdlib | 1.24.12 |
| Low | DEBIAN-CVE-2026-86420 | imagemagick | no fix listed |
| Low | DEBIAN-CVE-2026-9547 | curl | no fix listed |
| Low | GHSA-6426-9fv3-65x8 | django | 5.2.11 |
| Low | PYSEC-2026-3732 | nltk | 3.9.4 |
| Low | DEBIAN-CVE-2026-25833 | mbedtls | no fix listed |
| Low | DEBIAN-CVE-2025-8177 | tiff | no fix listed |
| Low | PYSEC-2026-3731 | nltk | 3.10.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 7.6.14latest | 5 months ago | 2.20.13 | 031591,028 | 11,950 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.