StackRadar

nocodb 0.4.6 Helm chart

one-acre-fundVerified publisher

Scored 14 Sept 2026

A Helm chart for Kubernetes

Version 0.4.6 6 months agoapp version 0.258.0 0Artifact Hub

nocodb 0.4.6 deploys 3 container images: library/postgres, library/busybox and nocodb/nocodb. Across them, 420 findings0 critical, 2 high. The highest contribution is GHSA-4v7x-pqxf-cx7m in golang.org/x/net v0.19.0, fixed in 0.23.0.

Radar Score

4,2190253365

420 findings over 3 of 3 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
library/postgresalpine00861634
library/busybox×2latest00000
nocodb/nocodb0.258.002453043,585

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

53 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumGHSA-5cgq-3rg8-m6cvgolang.org/x/crypto@v0.17.00.52.0
MediumGHSA-v778-237x-gjrcgolang.org/x/crypto@v0.17.00.31.0
MediumGHSA-2w6w-674q-4c4qhandlebars@4.7.84.7.9
MediumGHSA-fjxv-7rqg-78g4form-data@2.3.32.5.4
MediumGHSA-5j98-mcp5-4vw2glob@10.4.510.5.0
MediumGHSA-p77j-4mvh-x3m3google.golang.org/grpc@v1.60.11.79.3
MediumGHSA-43fc-jf86-j433axios@1.7.71.13.5
MediumALPINE-CVE-2026-19931curl@8.21.0-r08.22.0-r0
MediumGHSA-pq67-2wwv-3xjxtar-fs@2.1.12.1.2
MediumALPINE-CVE-2026-63073openssl@3.5.7-r03.5.8-r0
MediumGHSA-72xf-g2v4-qvf3tough-cookie@2.4.34.1.3
MediumALPINE-CVE-2026-18924curl@8.21.0-r08.22.0-r0
MediumGHSA-35jp-ww65-95whaxios@1.7.71.16.0
MediumALPINE-CVE-2025-9230openssl@3.1.7-r03.1.8-r1
MediumALPINE-CVE-2026-18798openssl@3.5.7-r03.5.8-r0
MediumGHSA-3h5v-q93c-6h6qws@8.14.28.17.1
MediumALPINE-CVE-2026-63076openssl@3.5.7-r03.5.8-r0
MediumGHSA-8r3f-844c-mc37google.golang.org/protobuf@v1.31.01.33.0
MediumGHSA-jr5f-v2jv-69x6axios@1.7.71.8.2
MediumGHSA-x527-x647-q7gggolang.org/x/crypto@v0.17.00.52.0
MediumGHSA-4hjh-wcwx-xvwjaxios@1.7.71.12.0
MediumGHSA-5528-5vmv-3xc2multer@1.4.4-lts.12.1.1
MediumGHSA-4r6h-8v6p-xvw6xlsx@0.20.3no fix listed
MediumGHSA-vgwf-h737-ff37golang.org/x/crypto@v0.17.00.52.0
MediumALPINE-CVE-2024-9143openssl@3.1.7-r03.1.7-r1
MediumGHSA-f5wc-c3c7-36mcgolang.org/x/crypto@v0.17.00.52.0
MediumGHSA-f23m-r3pf-42rhlodash@4.17.214.18.0
MediumGHSA-xxjr-mmjv-4gpglodash@4.17.214.17.23
MediumGHSA-v52c-386h-88mcmulter@1.4.4-lts.12.1.0
MediumGHSA-xf7r-hgr6-v32pmulter@1.4.4-lts.12.1.0
MediumGHSA-2v35-w6hq-6mfw@xmldom/xmldom@0.8.100.8.13
MediumALPINE-CVE-2026-14457openssl@3.5.7-r03.5.8-r0
MediumALPINE-CVE-2025-9232openssl@3.1.7-r03.1.8-r1
MediumGHSA-rm3j-f69w-wqmqgolang.org/x/crypto@v0.17.00.52.0
MediumALPINE-CVE-2026-80231curl@8.21.0-r08.22.0-r0
MediumGHSA-37ch-88jc-xwx2path-to-regexp@0.1.100.1.13
MediumGHSA-hcg3-q754-cr77golang.org/x/crypto@v0.17.00.35.0
MediumGHSA-8cj5-5rvv-wf4vtar-fs@2.1.12.1.3
MediumALPINE-CVE-2026-80229curl@8.21.0-r08.22.0-r0
MediumGHSA-3mfm-83xf-c92rhandlebars@4.7.84.7.9
MediumGHSA-xhpv-hc6g-r9c6handlebars@4.7.84.7.9
MediumGHSA-m7jm-9gc2-mpf2fast-xml-parser@4.5.04.5.4
MediumGHSA-p92q-9vqr-4j8vaxios@1.7.71.16.0
MediumGHSA-vj76-c3g6-qr5vtar-fs@2.1.12.1.4
MediumGHSA-6v2p-p543-phr9golang.org/x/oauth2@v0.15.00.27.0
MediumGHSA-5pgg-2g8v-p4x9xlsx@0.20.3no fix listed
MediumGHSA-jmr7-xgp7-cmfjfast-xml-parser@4.5.04.5.4
MediumGHSA-f6ww-3ggp-fr8h@xmldom/xmldom@0.8.100.8.13
MediumGHSA-96hv-2xvq-fx4pws@8.18.08.21.0
MediumGHSA-3ppc-4f35-3m26minimatch@3.1.23.1.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.4.6latest6 months ago0.258.002533654,219

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/one-acre-fund/nocodb.svg)](https://charts.stackradar.io/charts/one-acre-fund/nocodb)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.