StackRadar

onos-progran 1.2.7 Helm chart

opencord

Scored 15 Sept 2026

ONOS with progran APP

Version 1.2.7 5 years agoapp version 0.1.8 0Artifact Hub

onos-progran 1.2.7 deploys 2 container images: muluder/prograncontrollermcord and docker.elastic.co/beats/filebeat-oss. Across the 1 measured, 1,979 findings28 critical, 132 high 3 on CISA KEV. The highest contribution is UBUNTU-CVE-2018-17456 in git 1:2.7.4-0ubuntu1.3, fixed in 1:2.7.4-0ubuntu1.5.

Radar Score

38,88928132875943

1,979 findings over 1 of 2 images measured

KEV ×3 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
muluder/prograncontrollermcord0.1.82813287594338,889
docker.elastic.co/beats/filebeat-oss6.4.2unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

943 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2025-13462python2.7@2.7.12-1ubuntu0~16.04.3no fix listed
LowUBUNTU-CVE-2025-13462python3.5@3.5.2-2ubuntu0~16.04.4no fix listed
LowUBUNTU-CVE-2019-20386systemd@229-4ubuntu21229-4ubuntu21.27
LowUBUNTU-CVE-2026-56850nodejs@8.9.4-1nodesource1no fix listed
LowUBUNTU-CVE-2025-61985openssh@1:7.2p2-4ubuntu2.4no fix listed
LowUBUNTU-CVE-2026-21715nodejs@8.9.4-1nodesource1no fix listed
LowUBUNTU-CVE-2026-56847nodejs@8.9.4-1nodesource1no fix listed
LowUBUNTU-CVE-2026-58039nodejs@8.9.4-1nodesource1no fix listed
LowUBUNTU-CVE-2026-21716nodejs@8.9.4-1nodesource1no fix listed
LowUBUNTU-CVE-2025-55132nodejs@8.9.4-1nodesource1no fix listed
LowGHSA-c6rq-rjc2-86v2chownr@1.0.11.1.0
LowUBUNTU-CVE-2025-66382expat@2.1.0-7ubuntu0.16.04.3no fix listed
LowUBUNTU-CVE-2026-48936nodejs@8.9.4-1nodesource1no fix listed
LowUBUNTU-CVE-2025-6170libxml2@2.9.3+dfsg1-1ubuntu0.52.9.3+dfsg1-1ubuntu0.7+esm9
LowUBUNTU-CVE-2026-24515expat@2.1.0-7ubuntu0.16.04.32.1.0-7ubuntu0.16.04.5+esm11
LowUBUNTU-CVE-2026-40228systemd@229-4ubuntu21no fix listed
LowUBUNTU-CVE-2026-32778expat@2.1.0-7ubuntu0.16.04.3no fix listed
LowUBUNTU-CVE-2023-4016procps@2:3.3.10-4ubuntu2.32:3.3.10-4ubuntu2.5+esm1
LowUBUNTU-CVE-2026-15310python2.7@2.7.12-1ubuntu0~16.04.3no fix listed
LowUBUNTU-CVE-2026-15310python3.5@3.5.2-2ubuntu0~16.04.4no fix listed
LowUBUNTU-CVE-2026-1485glib2.0@2.48.2-0ubuntu1no fix listed
LowUBUNTU-CVE-2026-53910diffutils@1:3.3-31:3.3-3ubuntu0.1~esm1
LowUBUNTU-CVE-2026-6879python3.5@3.5.2-2ubuntu0~16.04.4no fix listed
LowUBUNTU-CVE-2026-6879python2.7@2.7.12-1ubuntu0~16.04.3no fix listed
LowUBUNTU-CVE-2026-86137libxml2@2.9.3+dfsg1-1ubuntu0.5no fix listed
LowUBUNTU-CVE-2026-86141libxml2@2.9.3+dfsg1-1ubuntu0.5no fix listed
LowUBUNTU-CVE-2025-66861binutils@2.26.1-1ubuntu1~16.04.6no fix listed
LowUBUNTU-CVE-2026-47241ruby2.3@2.3.1-2~16.04.5no fix listed
LowUBUNTU-CVE-2026-18743popt@1.16-10no fix listed
LowUBUNTU-CVE-2026-35388openssh@1:7.2p2-4ubuntu2.4no fix listed
LowUBUNTU-CVE-2026-48617nodejs@8.9.4-1nodesource1no fix listed
LowUBUNTU-CVE-2026-18739popt@1.16-10no fix listed
LowUBUNTU-CVE-2026-18503python2.7@2.7.12-1ubuntu0~16.04.3no fix listed
LowUBUNTU-CVE-2026-18503python3.5@3.5.2-2ubuntu0~16.04.4no fix listed
LowUBUNTU-CVE-2026-28422vim@2:7.4.1689-3ubuntu1.22:7.4.1689-3ubuntu1.5+esm29
LowUBUNTU-CVE-2026-73283openssh@1:7.2p2-4ubuntu2.4no fix listed
LowUBUNTU-CVE-2026-6368glibc@2.23-0ubuntu9no fix listed
LowUBUNTU-CVE-2026-18839popt@1.16-10no fix listed
LowGHSA-2mj8-pj3j-h362bin-links@1.1.01.1.5
LowGHSA-gqf6-75v8-vr26bin-links@1.1.01.1.5
LowGHSA-v45m-2wcp-gg98bin-links@1.1.01.1.6
LowUBUNTU-CVE-2019-9619systemd@229-4ubuntu21no fix listed
LowUBUNTU-CVE-2025-11961libpcap@1.7.4-2no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.2.7latest5 years ago0.1.82813287594338,889

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/opencord/onos-progran.svg)](https://charts.stackradar.io/charts/opencord/onos-progran)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.