StackRadar

yeti 1.0.5 Helm chart

osdfir-infrastructureVerified publisher

Scored 14 Sept 2026

A Helm chart for Yeti Kubernetes deployments.

Version 1.0.5 1 year agoapp version latest 0Artifact Hub

yeti 1.0.5 deploys 4 container images: yetiplatform/yeti, library/arangodb, yetiplatform/yeti-frontend and bitnami/redis. Across the 3 measured, 628 findings0 critical, 5 high 1 on CISA KEV. The highest contribution is GHSA-86qp-5c8j-p5mr in starlette 0.46.2, fixed in 1.0.1.

Radar Score

6,5830588534

628 findings over 3 of 4 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

4 images
ImageTagVulnerabilitiesRadar Score
yetiplatform/yeti×2latest03422513,189
library/arangodb3.11.802121321,418
yetiplatform/yeti-frontendlatest00341511,976
bitnami/redis×27.2.4-debian-12-r16unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

493 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumGHSA-xxjr-mmjv-4gpglodash@4.17.214.17.23
MediumGHSA-vqfr-h8mv-ghfjh11@0.14.00.16.0
MediumDEBIAN-CVE-2020-14145openssh@1:10.0p1-7+deb13u4no fix listed
MediumDEBIAN-CVE-2026-8924curl@8.14.1-2+deb13u4no fix listed
MediumDEBIAN-CVE-2026-8376perl@5.40.1-65.40.1-6+deb13u1
MediumDEBIAN-CVE-2026-14457openssl@3.5.6-1~deb13u23.5.7-1~deb13u2
MediumGHSA-wvwj-cvrp-7pv5authlib@1.5.21.6.9
MediumGHSA-rm3j-f69w-wqmqgolang.org/x/crypto@v0.17.00.52.0
MediumGHSA-hcg3-q754-cr77golang.org/x/crypto@v0.17.00.35.0
MediumDEBIAN-CVE-2026-66046expat@2.8.3-1~deb13u1no fix listed
MediumDEBIAN-CVE-2026-66033libssh2@1.11.1-1+deb13u11.11.1-1+deb13u2
MediumDEBIAN-CVE-2026-52490tiff@4.7.0-3+deb13u3no fix listed
MediumDEBIAN-CVE-2026-80229curl@8.14.1-2+deb13u4no fix listed
MediumDEBIAN-CVE-2026-8927curl@8.14.1-2+deb13u4no fix listed
MediumDEBIAN-CVE-2015-9019libxslt@1.1.35-1.2+deb13u3no fix listed
MediumGHSA-58pv-8j8x-9vj2jaraco-context@5.3.06.1.0
MediumDEBIAN-CVE-2024-52005git@1:2.47.3-0+deb13u1no fix listed
MediumGHSA-3ppc-4f35-3m26minimatch@5.1.65.1.7
MediumGHSA-jr27-m4p2-rc6rpyasn1@0.4.80.6.3
MediumDEBIAN-CVE-2019-1010025glibc@2.41-12+deb13u3no fix listed
LowDEBIAN-CVE-2026-57433perl@5.40.1-65.40.1-6+deb13u1
LowPYSEC-2026-2132click@8.1.88.3.3
LowDEBIAN-CVE-2026-8926curl@8.14.1-2+deb13u4no fix listed
LowDEBIAN-CVE-2026-6653libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3no fix listed
LowGHSA-9493-h29p-rfm2github.com/opencontainers/runc@v1.1.121.2.8
LowDEBIAN-CVE-2026-13221perl@5.40.1-65.40.1-6+deb13u1
LowDEBIAN-CVE-2026-42496perl@5.40.1-65.40.1-6+deb13u1
LowGHSA-89gr-r52h-f8rxgolang.org/x/crypto@v0.17.00.52.0
LowGHSA-pp6c-gr5w-3c5gpython-multipart@0.0.180.0.27
LowGHSA-jppx-rxg9-jmrxgolang.org/x/crypto@v0.17.00.52.0
LowDEBIAN-CVE-2026-14456openssl@3.5.6-1~deb13u23.5.7-1~deb13u2
LowGHSA-mh63-6h87-95cpgithub.com/golang-jwt/jwt@v3.2.2+incompatibleno fix listed
LowDEBIAN-CVE-2026-82209curl@8.14.1-2+deb13u4no fix listed
LowDEBIAN-CVE-2026-66032libssh2@1.11.1-1+deb13u11.11.1-1+deb13u2
LowDEBIAN-CVE-2026-80255curl@8.14.1-2+deb13u4no fix listed
LowGHSA-ph9p-34f9-6g65tmp@0.0.330.2.6
LowGHSA-36p7-vc44-83pfchromadb@1.5.7no fix listed
LowDEBIAN-CVE-2026-12087perl@5.40.1-65.40.1-6+deb13u1
LowDEBIAN-CVE-2025-1153binutils@2.44-3no fix listed
LowDEBIAN-CVE-2018-20673binutils@2.44-3no fix listed
LowGHSA-7f5h-v6xp-fcq8starlette@0.46.20.49.1
LowGHSA-pq5p-34cr-23v9authlib@1.5.21.6.5
LowGHSA-rgw5-rvv9-x895brace-expansion@2.0.12.1.4
LowDEBIAN-CVE-2026-13608curl@8.14.1-2+deb13u4no fix listed
LowDEBIAN-CVE-2026-63072openssl@3.5.6-1~deb13u23.5.7-1~deb13u2
LowDEBIAN-CVE-2026-85091zlib@1:1.3.dfsg+really1.3.1-1+b1no fix listed
LowDEBIAN-CVE-2026-60002openssh@1:10.0p1-7+deb13u4no fix listed
LowDEBIAN-CVE-2026-80230curl@8.14.1-2+deb13u4no fix listed
LowDEBIAN-CVE-2009-4487nginx@1.31.4-1~trixieno fix listed
LowGHSA-2wm9-hf6c-p5crchromadb@1.5.7no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.5latest1 year agolatest05885346,583

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/osdfir-infrastructure/yeti.svg)](https://charts.stackradar.io/charts/osdfir-infrastructure/yeti)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.