StackRadar

clowder2 1.9.7 Helm chart

ncsaVerified publisher

Scored 15 Sept 2026

Open Source Data Management for Long Tail Data. Clowder is a customizable and scalable data management framework to support any data format and multiple research domains.

Version 1.9.7 9 months agoapp version 2.0.0-beta.4 1Artifact Hub

clowder2 1.9.7 deploys 12 container images: bitnamilegacy/minio, bitnamilegacy/mongodb, clowder/clowder2-backend, clowder/clowder2-frontend and 8 more. Across them, 3,295 findings14 critical, 33 high 12 on CISA KEV. The highest contribution is GHSA-f58c-gq56-vjjf in tika-core 2.7.0, fixed in 3.2.2.

Radar Score

37,44114334772,768

3,295 findings over 12 of 12 images measured

KEV ×12 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

12 images
ImageTagVulnerabilitiesRadar Score
bitnamilegacy/minio2023.12.2302261802,291
bitnamilegacy/mongodb5.0.1016312062,886
clowder/clowder2-backend2.0.0-beta.402462423,257
clowder/clowder2-frontend2.0.0-beta.40120741,092
clowder/clowder2-heartbeat2.0.0-beta.402462423,257
clowder/clowder2-messages2.0.0-beta.402462423,257
bitnamilegacy/os-shell×412-debian-12-r1636633074,478
bitnamilegacy/elasticsearch×88.12.2761005337,621
bitnamilegacy/postgresql15.5.020251251,897
library/busybox1.2800000
bitnamilegacy/keycloak20.0.513594525,466
bitnamilegacy/rabbitmq3.10.803151651,939

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

1,208 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2023-29383shadow@1:4.13+dfsg1-1+b11:4.13+dfsg1-1+deb12u1
LowGHSA-2hm2-hc3v-44h9mistune@3.0.23.3.0
LowDEBIAN-CVE-2026-90781alsa-lib@1.2.8-1+b1no fix listed
LowGHSA-29wx-vh33-7x7rgithub.com/golang-jwt/jwt/v4@v4.5.04.5.1
LowGO-2026-5025golang.org/x/net@v0.19.00.55.0
LowGO-2026-4970stdlib@go1.20.131.25.12
LowGHSA-jfvp-7x6p-h2pvgithub.com/opencontainers/runc@v1.1.01.1.14
LowGHSA-vffw-93wf-4j4qpython-multipart@0.0.60.0.30
LowDEBIAN-CVE-2025-15224curl@7.88.1-10+deb12u5no fix listed
LowDEBIAN-CVE-2026-22185openldap@2.5.13+dfsg-5no fix listed
LowGO-2026-5027golang.org/x/net@v0.19.00.55.0
LowGO-2026-5029golang.org/x/net@v0.19.00.55.0
LowGO-2026-5030golang.org/x/net@v0.19.00.55.0
LowGHSA-58qw-9mgm-455vpip@23.0.126.1
LowGHSA-5545-r4hg-rj4mkeycloak-quarkus-server@20.0.526.0.6
LowDEBIAN-CVE-2026-3713libpng1.6@1.6.39-2no fix listed
LowDEBIAN-CVE-2026-42250bzip2@1.0.8-5+b1no fix listed
LowBIT-java-2026-22018Java@17.0.10-13-21.8.0
LowBIT-java-2026-22018java@17.0.6-10-41.8.0
LowDEBIAN-CVE-2025-9820gnutls28@3.7.9-2+deb12u53.7.9-2+deb12u6
LowBIT-java-2026-60589java@17.0.6-10-41.8.0
LowBIT-java-2026-60589Java@17.0.10-13-21.8.0
LowDEBIAN-CVE-2026-43895jq@1.6-2.11.6-2.1+deb12u2
LowGHSA-6jv3-5f52-599mpython-multipart@0.0.60.0.30
LowBIT-postgresql-2026-14666postgresql@15.5.0-4214.24.0
LowBIT-postgresql-2026-14666PostgreSQL@15.5.0-4214.24.0
LowBIT-java-2026-47010java@17.0.6-10-41.8.0
LowBIT-java-2026-47010Java@17.0.10-13-21.8.0
LowGO-2026-4602stdlib@go1.20.131.25.8
LowGHSA-5v8v-xvjv-57x7keycloak-services@20.0.526.4.13
LowGHSA-c25h-c27q-5qpvkeycloak-ldap-federation@20.0.522.0.12
LowALPINE-CVE-2026-27456util-linux@2.41-r92.41.6-r0
LowDEBIAN-CVE-2026-27456util-linux@2.38.1-5+deb12u3no fix listed
LowDEBIAN-CVE-2026-18508tar@1.34+dfsg-1.2+deb12u1no fix listed
LowDEBIAN-CVE-2025-68972gnupg2@2.2.40-1.1+deb12u1no fix listed
LowGHSA-7fpj-9hr8-28vhkeycloak-services@20.0.522.0.10
LowGHSA-63v5-26vq-m4vmkeycloak-services@20.0.5no fix listed
LowDEBIAN-CVE-2026-89160pcre2@10.42-110.42-1+deb12u1
LowBIT-postgresql-2024-10977postgresql@15.5.0-4212.21.0
LowBIT-postgresql-2024-10977PostgreSQL@15.5.0-4212.21.0
LowBIT-mongodb-2025-6707mongodb@5.0.10-05.0.31
LowBIT-postgresql-2026-16241PostgreSQL@15.5.0-4214.24.0
LowBIT-postgresql-2026-16241postgresql@15.5.0-4214.24.0
LowGHSA-gg57-587f-h5v6infinispan-core@13.0.10.Final14.0.25.Final
LowGHSA-gg57-587f-h5v6infinispan-commons@13.0.10.Final14.0.25.Final
LowGHSA-gg57-587f-h5v6infinispan-client-hotrod@13.0.10.Final14.0.25.Final
LowGHSA-gg57-587f-h5v6infinispan-cachestore-remote@13.0.10.Final14.0.25.Final
LowDEBIAN-CVE-2022-3219gnupg2@2.2.40-1.1+deb12u1no fix listed
LowBIT-postgresql-2026-6469postgresql@15.5.0-4214.24.0
LowBIT-postgresql-2026-6469PostgreSQL@15.5.0-4214.24.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.9.7latest9 months ago2.0.0-beta.414334772,76837,441

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/ncsa/clowder2.svg)](https://charts.stackradar.io/charts/ncsa/clowder2)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.