StackRadar

dify-enterprise 3.9.8 Helm chart

openshift

Scored 14 Sept 2026

Release https://langgenius.github.io/dify-helm/

Version 3.9.8deploys tag 3.9.8-ubi9 0Artifact Hub

dify-enterprise 3.9.8 deploys 13 container images: langgenius/dify-ee-api, langgenius/dify-ee-audit, langgenius/dify-ee-collector, langgenius/dify-ee-enterprise and 9 more. Across the 10 measured, 547 findings0 critical, 0 high. The highest contribution is GHSA-p293-qw3h-jr36 in next 16.2.6, fixed in 16.3.3. Chart.yaml declares kubeVersion >=1.21.0; rendered for Kubernetes 1.21.0.

Radar Score

4,6600020527

547 findings over 10 of 13 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

13 images
ImageTagVulnerabilitiesRadar Score
langgenius/dify-ee-api×43.9.8-ubi9not yet scanned
langgenius/dify-ee-audit3.9.8-ubi900051387
langgenius/dify-ee-collector3.9.8-ubi900053399
langgenius/dify-ee-enterprise3.9.8-ubi900050383
langgenius/dify-ee-enterprise-frontend3.9.8-ubi9001056739
langgenius/dify-ee-gateway3.9.8-ubi900054404
registry.redhat.io/rhel10/squid10.2-1784142920unmeasured
langgenius/dify-ee-plugin-connector3.9.8-ubi900052404
langgenius/dify-ee-plugin-crd3.9.8-ubi900050384
langgenius/dify-ee-plugin-daemon-serverless3.9.8-ubi900051399
langgenius/dify-ee-plugin-manager3.9.8-ubi900053408
langgenius/dify-ee-sandbox3.9.8-ubi9not yet scanned
langgenius/dify-ee-web3.9.8-ubi9001057753

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

114 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumGHSA-p293-qw3h-jr36next@16.2.616.3.3
MediumGHSA-m99w-x7hq-7vfjnext@16.2.616.2.11
MediumGHSA-grv7-fg5c-xmjgbraces@3.0.23.0.3
MediumGHSA-6gpp-xcg3-4w24next@16.2.616.2.11
MediumGHSA-89xv-2m56-2m9xnext@16.2.616.2.11
MediumGHSA-p9j2-gv94-2wf4next@16.2.616.2.11
MediumRHSA-2026:55601nodejs-nodemon@3.0.3-3.module+el9.8.0+24355+35d95b590:3.1.14-2.module+el9.8.0+24637+e0b636e5
MediumRHSA-2026:55603nodejs-nodemon@3.0.3-3.module+el9.8.0+24355+35d95b590:3.1.14-3.module+el9.8.0+24638+75f46aee
MediumRHSA-2026:55603nodejs@1:24.18.0-1.module+el9.8.0+24456+b244c3b41:24.18.0-6.module+el9.8.0+24638+75f46aee
MediumGHSA-3ppc-4f35-3m26minimatch@3.1.23.1.3
LowGHSA-vxpw-j846-p89qundici@6.26.06.27.0
LowGHSA-vp52-pcj8-j9qcgoogle.golang.org/grpc@v1.81.01.83.1
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.111.1.18
LowRHSA-2026:55440glib2@2.68.4-19.el9_8.10:2.68.4-19.el9_8.9
LowGHSA-wx67-qw84-cm4greact-server-dom-webpack@19.2.619.2.8
LowRHSA-2026:55439curl@7.76.1-40.el90:7.76.1-40.el9_8.5
LowGHSA-23hp-3jrh-7fpwtar@7.5.157.5.19
LowRHSA-2026:47057nodejs-nodemon@3.0.3-3.module+el9.8.0+24355+35d95b590:3.1.14-2.module+el9.8.0+24539+0ea88729
LowRHSA-2026:47057nodejs@1:24.18.0-1.module+el9.8.0+24456+b244c3b41:24.18.0-3.module+el9.8.0+24537+83ec84e1
LowRHSA-2026:47058nodejs-nodemon@3.0.3-3.module+el9.8.0+24355+35d95b590:3.1.14-1.module+el9.8.0+24540+c30b2ffe
LowRHSA-2026:42089glib2@2.68.4-19.el9_8.10:2.68.4-19.el9_8.2
LowGHSA-7r86-cg39-jmmjminimatch@3.1.23.1.3
LowRHSA-2026:61383nodejs-nodemon@3.0.3-3.module+el9.8.0+24355+35d95b590:3.1.14-2.module+el9.8.0+24709+804d6b5b
LowRHSA-2026:61386nodejs-nodemon@3.0.3-3.module+el9.8.0+24355+35d95b590:3.1.14-3.module+el9.8.0+24708+e71d2e1d
LowRHSA-2026:61386nodejs@1:24.18.0-1.module+el9.8.0+24456+b244c3b41:24.19.0-1.module+el9.8.0+24708+e71d2e1d
LowRHSA-2026:52674libarchive@3.5.3-9.el9_70:3.5.3-11.el9_8
LowGHSA-23c5-xmqv-rm74minimatch@3.1.23.1.4
LowGHSA-mh99-v99m-4gvgbrace-expansion@1.1.111.1.17
LowGHSA-8x88-c5mf-7j5wtar@7.5.157.5.18
LowGHSA-c2c7-rcm5-vvqjpicomatch@2.3.12.3.2
LowGHSA-q8wf-6r8g-63chnext@16.2.616.2.11
LowGHSA-mwp4-54f8-5fhrip-address@10.2.010.3.1
LowGHSA-r292-9mhp-454mtar@7.5.157.5.21
LowGHSA-w4pp-8pjf-rmxwpacote@21.5.021.5.1
LowGHSA-4xrf-jv44-h6hhip-address@10.2.010.2.2
LowGHSA-4c39-4ccg-62r3next@16.2.616.2.11
LowGHSA-955p-x3mx-jcvpnext@16.2.616.2.11
LowGHSA-hc8v-wwc9-vgxmgithub.com/go-git/go-git/v5@v5.19.15.19.2
LowGHSA-f886-m6hf-6m8vbrace-expansion@1.1.111.1.13
LowGHSA-22jq-vg5j-6vggip-address@10.2.010.2.1
LowGHSA-qgq7-7hm3-q39jgithub.com/go-git/go-git/v5@v5.19.15.19.2
LowRHSA-2026:42952glibc@2.34-272.el9_80:2.34-274.el9_8
LowGHSA-w8wr-v893-vjvptar@7.5.157.5.18
LowGHSA-4633-3j49-mh5qnext@16.2.616.2.11
LowRHSA-2026:64800glib2@2.68.4-19.el9_8.10:2.68.4-19.el9_8.10
LowGHSA-2xp9-vwfh-vxw4next@16.2.616.3.3
LowRHSA-2026:58936sqlite@3.34.1-10.el9_80:3.34.1-11.el9_8
LowGHSA-qc2q-p7wx-3px3google.golang.org/grpc@v1.81.01.83.1
LowRHSA-2026:50147libgcrypt@1.10.0-11.el90:1.10.0-13.el9_8
LowGHSA-gvwx-54wh-qm9jtar@7.5.157.5.17

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.9.8latest3.9.8-ubi900205274,660

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/openshift/dify-enterprise.svg)](https://charts.stackradar.io/charts/openshift/dify-enterprise)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.