StackRadar

firehose-core 1.2.6 Helm chart

nodeifyVerified publisher

Scored 14 Sept 2026

A Helm chart for Kubernetes

Version 1.2.6 4 months agoapp version v1.12.3 0Artifact Hub

firehose-core 1.2.6 deploys 2 container images: ghcr.io/streamingfast/firehose-core and sigp/lighthouse. Across them, 619 findings0 critical, 7 high 1 on CISA KEV. The highest contribution is UBUNTU-CVE-2025-15467 in openssl 3.0.2-0ubuntu1.21, with no fix listed.

Radar Score

6,4550786526

619 findings over 2 of 2 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/streamingfast/firehose-core×5v1.12.304514174,668
sigp/lighthouselatest-amd6403351091,787

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

496 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGO-2025-4015stdlib@go1.18.51.24.8
LowGO-2026-6218stdlib@go1.24.101.25.13
LowGO-2026-4441golang.org/x/net@v0.41.00.45.0
LowUBUNTU-CVE-2025-45582tar@1.34+dfsg-1ubuntu0.1.22.04.21.34+dfsg-1ubuntu0.1.22.04.4
LowUBUNTU-CVE-2026-15534perl@5.34.0-3ubuntu1.55.34.0-3ubuntu1.9
LowGO-2025-3373stdlib@go1.18.51.22.11
LowGO-2026-5970golang.org/x/text@v0.3.70.39.0
LowGO-2025-4155stdlib@go1.24.101.24.11
LowUBUNTU-CVE-2025-14017curl@8.5.0-2ubuntu10.68.5.0-2ubuntu10.7
LowGO-2024-2888stdlib@go1.18.51.21.11
LowUBUNTU-CVE-2026-86144libxml2@2.9.14+dfsg-1.3ubuntu3.6no fix listed
LowGO-2025-4008stdlib@go1.18.51.24.8
LowGO-2025-4010stdlib@go1.18.51.24.8
LowUBUNTU-CVE-2024-10041pam@1.4.0-11ubuntu2.6no fix listed
LowUBUNTU-CVE-2026-59850libssh@0.10.6-2ubuntu0.20.10.6-2ubuntu0.5
LowGO-2023-1840stdlib@go1.18.51.19.10
LowUBUNTU-CVE-2025-0167curl@8.5.0-2ubuntu10.68.5.0-2ubuntu10.8
LowUBUNTU-CVE-2026-40612jq@1.7.1-3ubuntu0.24.04.1no fix listed
LowUBUNTU-CVE-2026-44777jq@1.7.1-3ubuntu0.24.04.1no fix listed
LowUBUNTU-CVE-2026-50812sqlite3@3.45.1-1ubuntu2.53.45.1-1ubuntu2.7
LowGO-2025-4014stdlib@go1.18.51.24.8
LowUBUNTU-CVE-2026-41256jq@1.7.1-3ubuntu0.24.04.1no fix listed
LowGO-2025-3503stdlib@go1.18.51.23.7
LowUBUNTU-CVE-2026-18938p11-kit@0.24.0-6build10.24.0-6ubuntu0.1
LowUBUNTU-CVE-2026-0989libxml2@2.9.14+dfsg-1.3ubuntu3.62.9.14+dfsg-1.3ubuntu3.7
LowGO-2026-4976stdlib@go1.24.101.25.10
LowUBUNTU-CVE-2025-6052glib2.0@2.80.0-6ubuntu3.42.80.0-6ubuntu3.6
LowUBUNTU-CVE-2025-5278coreutils@8.32-4.1ubuntu1.28.32-4.1ubuntu1.4
LowUBUNTU-CVE-2026-47770jq@1.7.1-3ubuntu0.24.04.1no fix listed
LowGO-2026-5856stdlib@go1.24.101.25.12
LowUBUNTU-CVE-2026-22795openssl@3.0.2-0ubuntu1.21no fix listed
LowGO-2025-4007stdlib@go1.18.51.24.9
LowGO-2026-6355golang.org/x/crypto@v0.40.00.56.0
LowGO-2026-4980stdlib@go1.24.101.25.10
LowUBUNTU-CVE-2026-42770openssl@3.0.2-0ubuntu1.213.0.2-0ubuntu1.25
LowGO-2026-5039stdlib@go1.24.101.25.11
LowUBUNTU-CVE-2025-3360glib2.0@2.80.0-6ubuntu3.42.80.0-6ubuntu3.6
LowUBUNTU-CVE-2026-41257jq@1.7.1-3ubuntu0.24.04.1no fix listed
LowUBUNTU-CVE-2026-1484glib2.0@2.80.0-6ubuntu3.42.80.0-6ubuntu3.8
LowGO-2025-4013stdlib@go1.18.51.24.8
LowGO-2025-3849stdlib@go1.18.51.23.12
LowGO-2026-4946stdlib@go1.24.101.25.9
LowGO-2022-0646github.com/aws/aws-sdk-go@v1.49.6no fix listed
LowUBUNTU-CVE-2026-54370acl@2.3.1-1no fix listed
LowUBUNTU-CVE-2026-56412expat@2.6.1-2ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-56131expat@2.6.1-2ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-50219expat@2.6.1-2ubuntu0.3no fix listed
LowUBUNTU-CVE-2025-15649perl@5.34.0-3ubuntu1.5no fix listed
LowGO-2026-4603stdlib@go1.24.101.25.8
LowUBUNTU-CVE-2026-0864python3.12@3.12.3-1ubuntu0.9no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.2.6latest4 months agov1.12.307865266,455

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/nodeify/firehose-core.svg)](https://charts.stackradar.io/charts/nodeify/firehose-core)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.