StackRadar

kobotoolbox Helm chart

one-acre-fundVerified publisher

Scored 15 Sept 2026

KoboToolbox field data collection solution

Latest 0.7.4 3 years agoApp version not verified against the render 2Artifact Hub

kobotoolbox 0.7.4 deploys 9 container images: bitnami/mongodb, library/busybox, enketo/enketo-express, jwilder/dockerize and 5 more. Across the 6 measured, 1,357 findings7 critical, 29 high 19 on CISA KEV. The highest contribution is GHSA-j7hp-h8jx-5ppr in pillow 9.1.0, fixed in 10.0.1.

Radar Score

18,518729349972

1,357 findings over 6 of 9 images measured

KEV ×19 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

9 images
ImageTagVulnerabilitiesRadar Score
bitnami/mongodb5.0.10-debian-11-r3unmeasured
library/busyboxlatest00000
enketo/enketo-express3.0.435962785,324
jwilder/dockerizelatest00554502
library/nginx1.210414631,126
kobotoolbox/kobocat2.022.24a27922234,510
kobotoolbox/kpi2.022.24d2131423547,056
bitnami/postgresql14.5.0-debian-11-r35unmeasured
bitnami/redis×26.2.7-debian-11-r3unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

887 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-jp4c-xjxw-mgf9pip@22.2.126.1
LowDLA-4365-1unbound@1.13.1-11.13.1-1+deb11u6
LowGO-2026-6354golang.org/x/crypto@v0.45.00.56.0
LowGO-2026-4982stdlib@go1.17.11.25.10
LowGO-2026-6091stdlib@go1.17.11.25.13
LowGHSA-wjx4-4jcj-g98jpillow@9.1.012.2.0
LowGO-2025-3750stdlib@go1.17.11.23.10
LowGO-2026-4864stdlib@go1.17.11.25.9
LowGO-2025-3447stdlib@go1.17.11.22.12
LowGO-2026-4865stdlib@go1.17.11.25.9
LowGO-2026-4869stdlib@go1.17.11.25.9
LowGO-2026-4340stdlib@go1.17.11.24.12
LowGO-2025-4175stdlib@go1.17.11.24.11
LowGHSA-fhv5-28vv-h8m8pyjwt@2.3.02.13.0
LowGHSA-v6h2-p8h4-qcjwbrace-expansion@1.1.111.1.12
LowDLA-4424-1openjpeg2@2.4.0-32.4.0-3+deb11u2
LowGHSA-gwp4-mcv4-w95jjwcrypto@1.01.4
LowGHSA-v78c-4p63-2j6cmoment-timezone@0.5.330.5.35
LowGHSA-cfqr-cjx5-5jcmsqlparse@0.4.20.6.0
LowGHSA-993g-76c3-p5m4pyjwt@2.3.02.13.0
LowGHSA-4x4j-2g7c-83w6pillow@9.1.012.3.0
LowGO-2026-4403stdlib@go1.17.11.23.9
LowGO-2026-5025golang.org/x/net@v0.47.00.55.0
LowGHSA-2cm2-m3w5-gp2fvm2@3.9.53.11.2
LowGO-2026-4970stdlib@go1.17.11.25.12
LowGO-2026-5027golang.org/x/net@v0.47.00.55.0
LowGO-2026-5029golang.org/x/net@v0.47.00.55.0
LowGO-2026-5030golang.org/x/net@v0.47.00.55.0
LowGHSA-58qw-9mgm-455vpip@22.2.126.1
LowDLA-4096-1librabbitmq@0.10.0-10.10.0-1+deb11u1
LowGHSA-78xj-cgh5-2h22ip@1.1.51.1.9
LowGO-2026-4602stdlib@go1.17.11.25.8
LowGHSA-3h9f-r86x-qvjxdjango@2.2.285.2.16
LowDLA-4156-1openssh@1:8.4p1-5+deb11u11:8.4p1-5+deb11u5
LowDLA-4225-1gdk-pixbuf@2.42.2+dfsg-12.42.2+dfsg-1+deb11u3
LowDLA-4435-1libsodium@1.0.18-11.0.18-1+deb11u1
LowDLA-4469-1alsa-lib@1.2.4-1.11.2.4-1.1+deb11u1
LowGHSA-7rx3-28cr-v5whhandlebars@4.7.74.7.9
LowGHSA-xhjh-pmcv-23jwaxios@0.21.40.31.1
LowGHSA-923m-gv2p-w5qpdjango@2.2.285.2.15
LowGHSA-38r7-794h-5758webpack@5.72.05.104.0
LowGHSA-8fgc-7cc6-rx7xwebpack@5.72.05.104.1
LowDLA-4319-1libxml2@2.9.10+dfsg-6.7+deb11u22.9.10+dfsg-6.7+deb11u9
LowDLA-4437-1gnupg2@2.2.27-2+deb11u12.2.27-2+deb11u3
LowGHSA-px8h-6qxv-m22qwerkzeug@2.0.32.2.3
LowGHSA-8cjm-8mp7-r2xfdjango@2.2.285.2.15
LowGHSA-h7pc-vwp9-298gdjango@2.2.285.2.15
LowGO-2026-5024golang.org/x/sys@v0.0.0-20210908233432-aa78b53d33650.44.0
LowGHSA-76c9-3jph-rj3qon-headers@1.0.21.1.0
LowDLA-2797-1tzdata@2021a-0+deb9u12021a-0+deb9u2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.7.4latest3 years ago72934997218,518

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/one-acre-fund/kobotoolbox.svg)](https://charts.stackradar.io/charts/one-acre-fund/kobotoolbox)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.