StackRadar

voltha-infra 2.14.0 Helm chart

opencord

Scored 15 Sept 2026

A Helm chart to install the required infrastructure for VOLTHA

Version 2.14.0 1 year agodeploys tag 0.3.5 0Artifact Hub

voltha-infra 2.14.0 deploys 10 container images: voltha/bbsim-sadis-server, freeradius/freeradius-server, opencord/onos-classic-helm-utils, bitnami/etcd and 6 more. Across the 6 measured, 2,638 findings27 critical, 97 high 11 on CISA KEV. The highest contribution is UBUNTU-CVE-2020-1472 in samba 2:4.7.6+dfsg~ubuntu-0ubuntu2.15, fixed in 2:4.7.6+dfsg~ubuntu-0ubuntu2.20.

Radar Score

41,08827977771,737

2,638 findings over 6 of 10 images measured

KEV ×11 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

10 images
ImageTagVulnerabilitiesRadar Score
voltha/bbsim-sadis-server0.3.513562673,720
freeradius/freeradius-server3.0.21133228169515,722
opencord/onos-classic-helm-utils0.1.018662233,880
bitnami/etcd3.5.6-debian-11-r10unmeasured
bitnami/zookeeper3.8.0-debian-11-r65unmeasured
bitnami/kafka3.3.1-debian-11-r25unmeasured
library/ubuntu16.0412671212,772
atomix/atomix3.1.12025961184,907
tutum/dnsutilslatestnot yet scanned
voltha/voltha-onos5.1.8112721131310,087

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

1,670 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-8xfc-gm6g-vgpvbcprov-jdk15on@1.691.78
LowGHSA-676x-f7gg-47vcnetty-resolver-dns@4.1.27.Final4.1.135.Final
LowUBUNTU-CVE-2024-33602glibc@2.27-3ubuntu1.62.27-3ubuntu1.6+esm3
LowUBUNTU-CVE-2021-2226mysql-5.7@5.7.29-0ubuntu0.18.04.15.7.34-0ubuntu0.18.04.1
LowGHSA-mjmq-gwgm-5qhmsshd-sftp@2.5.12.9.3
LowGHSA-mjmq-gwgm-5qhmsshd-core@1.7.02.1.0
LowUBUNTU-CVE-2025-30693mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed
LowGHSA-p436-gjf2-799pgithub.com/docker/cli@v20.10.5+incompatible29.2.0
LowUBUNTU-CVE-2021-2022mysql-5.7@5.7.29-0ubuntu0.18.04.15.7.33-0ubuntu0.18.04.1
LowUBUNTU-CVE-2026-14679postgresql-10@10.12-0ubuntu0.18.04.1no fix listed
LowUBUNTU-CVE-2020-14867mysql-5.7@5.7.29-0ubuntu0.18.04.15.7.32-0ubuntu0.18.04.1
LowUBUNTU-CVE-2026-4046glibc@2.27-3ubuntu1.6no fix listed
LowUBUNTU-CVE-2019-14855gnupg2@2.2.4-1ubuntu1.22.2.4-1ubuntu1.3
LowUBUNTU-CVE-2019-14855gnupg@1.4.20-1ubuntu3.3no fix listed
LowGHSA-wg6q-6289-32hpbcpkix-jdk15on@1.661.84
LowGHSA-hmr7-m48g-48f6jetty-http@9.4.43.v202106299.4.52
LowGO-2022-0537stdlib@go1.16.51.17.13
LowGHSA-4h8f-2wvx-gg5wbcprov-jdk15on@1.691.78
LowGHSA-4c37-7m5h-c8m9org.apache.felix.webconsole@4.7.04.9.10
LowUBUNTU-CVE-2026-48959perl@5.26.1-6ubuntu0.7no fix listed
LowUBUNTU-CVE-2021-20251samba@2:4.7.6+dfsg~ubuntu-0ubuntu2.15no fix listed
LowUBUNTU-CVE-2026-5928glibc@2.27-3ubuntu1.6no fix listed
LowUBUNTU-CVE-2020-14553mysql-5.7@5.7.29-0ubuntu0.18.04.15.7.31-0ubuntu0.18.04.1
LowUBUNTU-CVE-2026-3833gnutls28@3.5.18-1ubuntu1.63.5.18-1ubuntu1.6+esm3
LowGHSA-rc4r-wh2q-q6c4github.com/docker/docker@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible20.10.18
LowGHSA-wjxj-5m7g-mg7qbcprov-jdk15on@1.69no fix listed
LowDSA-5202-1unzip@6.0-266.0-26+deb11u1
LowUBUNTU-CVE-2025-50078mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed
LowUBUNTU-CVE-2026-60163mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed
LowGHSA-mq39-4gv4-mvpxgithub.com/docker/docker@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible23.0.11
LowUBUNTU-CVE-2026-60081libdbi-perl@1.640-1no fix listed
LowUBUNTU-CVE-2021-2171mysql-5.7@5.7.29-0ubuntu0.18.04.15.7.34-0ubuntu0.18.04.1
LowUBUNTU-CVE-2026-6478postgresql-10@10.12-0ubuntu0.18.04.1no fix listed
LowGHSA-v2xm-76pq-phcfclassgraph@4.2.34.8.112
LowUBUNTU-CVE-2020-14559mysql-5.7@5.7.29-0ubuntu0.18.04.15.7.31-0ubuntu0.18.04.1
LowUBUNTU-CVE-2024-20964mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed
LowUBUNTU-CVE-2026-6791glibc@2.27-3ubuntu1.6no fix listed
LowUBUNTU-CVE-2026-60315mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed
LowUBUNTU-CVE-2025-21490mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed
LowUBUNTU-CVE-2025-21504mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed
LowUBUNTU-CVE-2024-21166mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed
LowUBUNTU-CVE-2025-64720libpng1.6@1.6.34-1ubuntu0.18.04.21.6.34-1ubuntu0.18.04.2+esm1
LowUBUNTU-CVE-2026-8458curl@7.58.0-2ubuntu3.197.58.0-2ubuntu3.24+esm9
LowUBUNTU-CVE-2025-4207postgresql-10@10.12-0ubuntu0.18.04.1no fix listed
LowUBUNTU-CVE-2026-76641expat@2.2.5-3ubuntu0.2no fix listed
LowUBUNTU-CVE-2025-50083mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed
LowUBUNTU-CVE-2026-6253curl@7.58.0-2ubuntu3.19no fix listed
LowUBUNTU-CVE-2020-27618glibc@2.27-3ubuntu1.22.27-3ubuntu1.5
LowUBUNTU-CVE-2025-50076mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed
LowUBUNTU-CVE-2025-50082mysql-5.7@5.7.29-0ubuntu0.18.04.1no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.14.0latest1 year ago0.3.527977771,73741,088

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/opencord/voltha-infra.svg)](https://charts.stackradar.io/charts/opencord/voltha-infra)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.