StackRadar

kobotoolbox Helm chart

one-acre-fundVerified publisher

Scored 14 Sept 2026

KoboToolbox field data collection solution

Latest 0.7.4 3 years agoApp version not verified against the render 2Artifact Hub

kobotoolbox 0.7.4 deploys 9 container images: bitnami/mongodb, library/busybox, enketo/enketo-express, jwilder/dockerize and 5 more. Across the 6 measured, 1,357 findings7 critical, 29 high 19 on CISA KEV. The highest contribution is GHSA-j7hp-h8jx-5ppr in pillow 9.1.0, fixed in 10.0.1.

Radar Score

18,517729349972

1,357 findings over 6 of 9 images measured

KEV ×19 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

9 images
ImageTagVulnerabilitiesRadar Score
bitnami/mongodb5.0.10-debian-11-r3unmeasured
library/busyboxlatest00000
enketo/enketo-express3.0.435962785,324
jwilder/dockerizelatest00554502
library/nginx1.210414631,126
kobotoolbox/kobocat2.022.24a27922234,510
kobotoolbox/kpi2.022.24d2131423547,056
bitnami/postgresql14.5.0-debian-11-r35unmeasured
bitnami/redis×26.2.7-debian-11-r3unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

887 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-537c-gmf6-5ccfcryptography@36.0.248.0.1
LowGHSA-5p4m-2wfm-xmqjjs-yaml@3.14.13.15.1
LowGHSA-v836-6xw4-9cx3vm2@3.9.53.11.6
LowDEBIAN-CVE-2022-38791mariadb-10.5@1:10.5.15-0+deb11u11:10.5.18-0+deb11u1
LowDLA-4346-1openjdk-11@11.0.16+8-1~deb11u111.0.29+6-1~deb11u1
LowDLA-4201-1libvpx@1.9.0-11.9.0-1+deb11u4
LowPYSEC-2026-2156gdal@3.2.23.13.0
LowDSA-5517-1libx11@2:1.7.2-12:1.7.2-1+deb11u2
LowGHSA-g4mx-q9vg-27p4urllib3@1.26.91.26.18
LowDLA-4146-1libxml2@2.9.10+dfsg-6.7+deb11u22.9.10+dfsg-6.7+deb11u7
LowGHSA-rrqc-c2jx-6jgvdjango@2.2.284.2.16
LowGO-2026-4870stdlib@go1.17.11.25.9
LowGO-2022-0532stdlib@go1.17.11.17.11
LowGO-2025-4009stdlib@go1.17.11.24.8
LowGO-2026-4947stdlib@go1.17.11.25.9
LowDLA-4176-1openssl@1.1.1n-0+deb11u21.1.1w-0+deb11u3
LowGHSA-x9hc-rw35-f44hstatic-eval@0.2.42.0.2
LowGHSA-4mjr-xmp4-gh2gqs@6.5.26.16.0
LowGO-2025-4006stdlib@go1.17.11.24.8
LowDLA-4489-1libvpx@1.9.0-11.9.0-1+deb11u5
LowDLA-3930-1libsepol@3.1-13.1-1+deb11u1
LowGO-2026-5037stdlib@go1.17.11.25.11
LowGO-2026-4971stdlib@go1.17.11.25.10
LowGHSA-48c2-rrv3-qjmpyaml@1.10.01.10.3
LowDLA-3029-1cups@2.2.1-8+deb9u62.2.1-8+deb9u8
LowGHSA-wp5r-2gw5-m7q7vm2@3.9.53.11.0
LowGO-2026-5972stdlib@go1.17.11.25.13
LowGO-2026-6088stdlib@go1.17.11.25.13
LowGO-2026-6089stdlib@go1.17.11.25.13
LowGO-2026-6090stdlib@go1.17.11.25.13
LowDLA-4440-1ffmpeg@7:4.3.4-0+deb11u17:4.3.9-0+deb11u2
LowGHSA-xx6v-rp6x-q39caxios@0.21.40.31.1
LowGO-2026-5038stdlib@go1.17.11.25.11
LowDLA-4181-1glibc@2.31-13+deb11u32.31-13+deb11u13
LowGO-2026-5942golang.org/x/net@v0.47.00.56.0
LowGHSA-jxfw-x594-9x9mmorgan@1.10.01.12.0
LowGHSA-898c-q2cr-xwhgaxios@0.21.40.32.0
LowGO-2025-4012stdlib@go1.17.11.24.8
LowDLA-2830-1tar@1.29b-1.11.29b-1.1+deb9u1
LowGO-2025-3956stdlib@go1.17.11.23.12
LowGO-2025-4011stdlib@go1.17.11.24.8
LowGO-2025-4015stdlib@go1.17.11.24.8
LowGO-2026-6218stdlib@go1.17.11.25.13
LowDLA-4241-1ffmpeg@7:4.3.4-0+deb11u17:4.3.9-0+deb11u1
LowDLA-4065-1krb5@1.18.3-6+deb11u11.18.3-6+deb11u6
LowGHSA-27jp-wm6q-gp25sqlparse@0.4.20.5.4
LowGHSA-3496-9g83-7v6xsqlparse@0.4.20.6.0
LowGHSA-r5m4-5vww-w9f5gdal@3.2.23.13.0RC1
LowGO-2025-3373stdlib@go1.17.11.22.11
LowPYSEC-2026-2275requests@2.27.12.33.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.7.4latest3 years ago72934997218,517

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/one-acre-fund/kobotoolbox.svg)](https://charts.stackradar.io/charts/one-acre-fund/kobotoolbox)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.