StackRadar

clowder2 1.9.7 Helm chart

ncsaVerified publisher

Scored 15 Sept 2026

Open Source Data Management for Long Tail Data. Clowder is a customizable and scalable data management framework to support any data format and multiple research domains.

Version 1.9.7 9 months agoapp version 2.0.0-beta.4 1Artifact Hub

clowder2 1.9.7 deploys 12 container images: bitnamilegacy/minio, bitnamilegacy/mongodb, clowder/clowder2-backend, clowder/clowder2-frontend and 8 more. Across them, 3,295 findings14 critical, 33 high 12 on CISA KEV. The highest contribution is GHSA-f58c-gq56-vjjf in tika-core 2.7.0, fixed in 3.2.2.

Radar Score

37,44114334772,768

3,295 findings over 12 of 12 images measured

KEV ×12 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

12 images
ImageTagVulnerabilitiesRadar Score
bitnamilegacy/minio2023.12.2302261802,291
bitnamilegacy/mongodb5.0.1016312062,886
clowder/clowder2-backend2.0.0-beta.402462423,257
clowder/clowder2-frontend2.0.0-beta.40120741,092
clowder/clowder2-heartbeat2.0.0-beta.402462423,257
clowder/clowder2-messages2.0.0-beta.402462423,257
bitnamilegacy/os-shell×412-debian-12-r1636633074,478
bitnamilegacy/elasticsearch×88.12.2761005337,621
bitnamilegacy/postgresql15.5.020251251,897
library/busybox1.2800000
bitnamilegacy/keycloak20.0.513594525,466
bitnamilegacy/rabbitmq3.10.803151651,939

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

1,208 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGO-2023-1621stdlib@go1.18.21.19.7
LowGHSA-mj87-hwqh-73pjpython-multipart@0.0.60.0.26
LowGO-2026-4981stdlib@go1.20.131.25.10
LowDEBIAN-CVE-2023-31439systemd@252.39-1~deb12u1no fix listed
LowGO-2025-3563stdlib@go1.20.131.23.8
LowGHSA-v87v-83h2-53w7mistune@3.0.23.2.1
LowPYSEC-2026-2206mistune@3.0.23.2.1
LowPYSEC-2026-2208mistune@3.0.23.2.1
LowPYSEC-2026-2209mistune@3.0.23.2.1
LowGHSA-5jmj-h7xm-6q6vjackson-databind@2.13.4.22.18.9
LowBIT-java-2024-21208Java@17.0.10-13-21.8.0
LowBIT-java-2024-21208java@17.0.6-10-41.8.0
LowBIT-postgresql-2024-10978postgresql@15.5.0-4212.21.0
LowBIT-postgresql-2024-10978PostgreSQL@15.5.0-4212.21.0
LowGO-2026-4977stdlib@go1.20.131.25.10
LowGO-2024-2610stdlib@go1.20.131.21.8
LowALPINE-CVE-2026-76957expat@2.7.3-r02.8.4-r0
LowDEBIAN-CVE-2023-31437systemd@252.39-1~deb12u1no fix listed
LowDEBIAN-CVE-2025-68973gnupg2@2.2.40-1.1+deb12u12.2.40-1.1+deb12u2
LowGO-2026-4986stdlib@go1.20.131.25.10
LowGHSA-966j-vmvw-g2g9aiohttp@3.11.103.13.4
LowGO-2026-4918golang.org/x/net@v0.19.00.53.0
LowGO-2026-4918stdlib@go1.20.131.25.10
LowBIT-keycloak-2026-18572keycloak@20.0.5-626.7.3
LowGO-2026-4337stdlib@go1.20.131.24.13
LowDEBIAN-CVE-2026-4438glibc@2.36-9+deb12u132.36-9+deb12u14
LowGHSA-mfg7-5gfp-c4w3netty-codec-dns@4.1.86.Final4.1.136.Final
LowGHSA-w853-jp5j-5j7ffilelock@3.16.13.20.1
LowGHSA-g4gc-rh26-m3p5keycloak-core@20.0.524.0.7
LowGHSA-fqjh-8322-vgrvkeycloak-services@20.0.5no fix listed
LowGHSA-qccp-gfcp-xxvcurllib3@1.26.202.7.0
LowDEBIAN-CVE-2024-28835gnutls28@3.7.9-2+deb12u23.7.9-2+deb12u3
LowDEBIAN-CVE-2023-31438systemd@252.39-1~deb12u1no fix listed
LowBIT-rabbitmq-2025-30219rabbitmq@3.10.8-14.0.3
LowBIT-keycloak-2026-16093keycloak@20.0.5-626.7.3
LowBIT-keycloak-2026-16108keycloak@20.0.5-626.7.3
LowDEBIAN-CVE-2026-56109alsa-lib@1.2.8-1+b1no fix listed
LowGHSA-fm6w-rrp3-2x4wkeycloak-services@20.0.526.2.13
LowBIT-keycloak-2026-37978keycloak@20.0.5-626.4.12
LowGHSA-rrv7-3mqf-hxfrkeycloak-services@20.0.526.6.2
LowGO-2026-4601stdlib@go1.20.131.25.8
LowDLA-3875-1gnutls28@3.7.1-5+deb11u33.7.1-5+deb11u6
LowBIT-java-2024-21012java@17.0.6-10-411.0.23
LowBIT-java-2024-21012Java@17.0.10-13-211.0.23
LowBIT-java-2025-30754java@17.0.6-10-41.8.0
LowBIT-java-2025-30754Java@17.0.10-13-21.8.0
LowALPINE-CVE-2026-56403expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-56404expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-56405expat@2.7.3-r02.8.2-r0
LowALPINE-CVE-2026-56408expat@2.7.3-r02.8.2-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.9.7latest9 months ago2.0.0-beta.414334772,76837,441

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/ncsa/clowder2.svg)](https://charts.stackradar.io/charts/ncsa/clowder2)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.