guacamole 0.0.5 Helm chart
quench-guacamoleVerified publisherScored 29 Sept 2026
Apache Guacamole, clientless remote desktop in the browser for RDP, VNC, SSH and telnet: the web app, the guacd proxy daemon and PostgreSQL in one install. Hardened by QuenchWorks as minimal, nonroot, 0-CVE images, cosign-signed and pinned by digest.
Version 0.0.5app version 1.6.0 (not verified against the render) 0Artifact Hub
guacamole 0.0.5 deploys 3 container images: ghcr.io/quenchworks/images/guacd, ghcr.io/quenchworks/images/guacamole and ghcr.io/quenchworks/images/postgresql. Across them, 54 findings — 0 critical, 0 high. The highest contribution is CGA-gv95-9q27-ppp9 in libssh2 1.11.1-r9, with no fix listed.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | digest-pinned | 00727 | 389 |
| ghcr.io/ | digest-pinned | 00010 | 80 |
| ghcr.io/ | digest-pinned | 00010 | 70 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | CGA-gv95-9q27-ppp9 | libssh2 | no fix listed |
| Medium | CGA-2h2j-pvgh-h98h | freerdp | no fix listed |
| Medium | CGA-5xmj-x822-8735 | freerdp | no fix listed |
| Medium | CGA-6v48-m285-87h7 | freerdp | no fix listed |
| Medium | CGA-9mx2-3w5x-w3m5 | freerdp | no fix listed |
| Medium | CGA-j4v4-7979-5vj3 | freerdp | no fix listed |
| Medium | CGA-v6p4-f448-f8qx | freerdp | no fix listed |
| Low | CGA-4jhh-fphw-7fqr | freerdp | no fix listed |
| Low | CGA-75pj-prxj-j69m | freerdp | no fix listed |
| Low | CGA-gq7j-g8cx-5rm3 | libssh2 | no fix listed |
| Low | CGA-5w5w-j84p-2rvw | libssh2 | no fix listed |
| Low | CGA-j7vf-wr2r-h6vf | libssh2 | no fix listed |
| Low | GHSA-q4xh-88c3-wmh7 | jackson-databind | 2.21.6 |
| Low | CGA-4c8q-pjfq-vwrf | freerdp | no fix listed |
| Low | CGA-chw6-hhw4-2rpp | freerdp | no fix listed |
| Low | CGA-2gqw-w47q-p6q3 | freerdp | no fix listed |
| Low | CGA-7ffg-5jmh-fv25 | freerdp | no fix listed |
| Low | CGA-fqvg-4g6m-5rqf | freerdp | no fix listed |
| Low | CGA-888g-2rh3-mh9x | freerdp | no fix listed |
| Low | CGA-4wfc-2rvc-856x | libssh2 | no fix listed |
| Low | CGA-42w3-fgjq-6w4x | libssh2 | no fix listed |
| Low | CGA-2h88-2h87-fgx5 | freerdp | no fix listed |
| Low | CGA-45vr-7x36-wwf2 | freerdp | no fix listed |
| Low | CGA-ccfh-mg58-846f | freerdp | no fix listed |
| Low | GHSA-gx83-3vf8-gh7j | jackson-databind | 2.21.6 |
| Low | CGA-hrv7-pwqg-466j | python-3.13 | no fix listed |
| Low | CGA-32c9-fmx5-865m | glibc-2.44 | no fix listed |
| Low | CGA-86q6-jgw4-4qvq | glibc-2.44 | no fix listed |
| Low | GHSA-wjgm-6hv5-3cvf | jackson-databind | 2.21.6 |
| Low | CGA-8fx3-25f8-fh5x | python-3.13 | no fix listed |
| Low | CGA-6cv2-mm79-q3h6 | glibc-2.44 | no fix listed |
| Low | CGA-36r3-9m2m-pwvx | python-3.13 | no fix listed |
| Low | CGA-3f6x-5fcp-398c | alsa-lib | no fix listed |
| Low | CGA-2727-9j94-3x3p | glibc-2.44 | no fix listed |
| Low | CGA-cvw6-9pj6-fx5j | openssl | no fix listed |
| Low | CGA-ww43-fhm7-mff3 | openssl | no fix listed |
| Low | CGA-5p62-38p7-f47c | python-3.13 | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.0.5latest | — | 1.6.0 | 00747 | 539 |
| 0.0.4 | — | 1.6.0 | 00747 | 531 |
| 0.0.2 | — | 1.6.0 | 00747 | 531 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.