StackRadar

kubecost 1.0.0 Helm chart

radar-baseVerified publisher

Scored 14 Sept 2026

A Helm chart for Kubecost cost analyzer. This chart is an overlay for the official cost-analyzer chart with custom resource limits configured for RADAR-K8s environments.

Version 1.0.0 20 days agodeploys tag v0.17.6 0Artifact Hub

kubecost 1.0.0 deploys 7 container images: gcr.io/kubecost1/kubecost-network-costs, gcr.io/kubecost1/cost-model, gcr.io/kubecost1/frontend, gcr.io/kubecost1/kubecost-modeling and 3 more. Across them, 834 findings6 critical, 7 high 1 on CISA KEV. The highest contribution is CGA-7rrv-fg72-6q59 in nginx-mainline 1.27.4-r0, fixed in 1.31.0-r0.

Radar Score

9,35567144676

834 findings over 7 of 7 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

7 images
ImageTagVulnerabilitiesRadar Score
gcr.io/kubecost1/kubecost-network-costsv0.17.6011951865
gcr.io/kubecost1/cost-model×3prod-2.6.320171571,795
gcr.io/kubecost1/frontendprod-2.6.31325481,214
gcr.io/kubecost1/kubecost-modelingv0.1.2221291191,943
ghcr.io/kiwigrid/k8s-sidecar1.29.1111838791
grafana/grafana11.4.001261601,800
quay.io/prometheus/prometheusv3.2.00010103947

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

75 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumGHSA-5cgq-3rg8-m6cvgolang.org/x/crypto@v0.32.00.52.0
MediumCGA-jwcx-pm9x-r4g6nginx-mainline@1.27.4-r01.31.2-r0
MediumCGA-3cc9-j23w-933vnginx-mainline@1.27.4-r01.31.3-r0
MediumCGA-7g5x-r9p8-435rnginx-mainline@1.27.4-r01.31.2-r0
MediumRHSA-2026:25239openssl@1:3.2.2-6.el9_5.11:3.5.5-4.el9_8
MediumCGA-mpgm-j4f6-x8m5openssl@3.3.2-r03.6.3-r0
MediumGHSA-v778-237x-gjrcgolang.org/x/crypto@v0.27.00.31.0
MediumGHSA-cx63-2mw6-8hw5setuptools@53.0.070.0.0
MediumGHSA-38jv-5279-wg99urllib3@2.3.02.6.3
MediumRHSA-2026:1087python-urllib3@1.26.5-6.el90:1.26.5-6.el9_7.1
MediumGHSA-p77j-4mvh-x3m3google.golang.org/grpc@v1.69.41.79.3
MediumRHSA-2025:10699libxml2@2.9.13-6.el9_5.10:2.9.13-10.el9_6
MediumGHSA-r9hx-vwmv-q579setuptools@53.0.065.5.1
MediumCGA-2mq2-wcqq-gj8wopenssl@3.3.2-r03.6.1-r0
MediumRHSA-2025:1330openssl@1:3.2.2-6.el9_51:3.2.2-6.el9_5.1
MediumPYSEC-2025-49setuptools@75.8.078.1.1
MediumALPINE-CVE-2025-3277sqlite@3.47.1-r03.48.0-r1
MediumRHSA-2026:20612gnutls@3.8.3-4.el9_40:3.8.10-4.el9_8
MediumRHSA-2025:0925bzip2@1.0.8-8.el90:1.0.8-10.el9_5
MediumRHSA-2026:24369unbound@1.16.2-8.el9_5.10:1.24.2-3.el9_8.1
MediumGHSA-j8r2-6x86-q33qrequests@2.25.12.31.0
MediumALPINE-CVE-2025-9230openssl@3.3.2-r43.3.5-r0
MediumPYSEC-2023-192urllib3@1.26.52.0.6
MediumCGA-2fmm-jpw2-g44pnginx-mainline@1.27.4-r01.29.7-r0
MediumALPINE-CVE-2024-12797openssl@3.3.2-r43.3.3-r0
MediumRHSA-2025:10136python3.9@3.9.21-1.el9_50:3.9.21-2.el9_6.1
MediumRHSA-2025:2679libxml2@2.9.13-6.el9_5.10:2.9.13-6.el9_5.2
MediumCGA-5hv9-mh2w-75gfnginx-mainline@1.27.4-r01.29.7-r0
MediumALPINE-CVE-2025-9231openssl@3.3.2-r43.3.5-r0
MediumPYSEC-2024-60idna@2.103.7
MediumGO-2026-4887github.com/docker/docker@v27.4.1+incompatibleno fix listed
MediumGHSA-xgrm-4fwx-7qm8github.com/jackc/pgx/v5@v5.5.55.9.0
MediumCGA-qpc2-2rgc-3w9vnginx-mainline@1.27.4-r01.29.7-r0
MediumRHSA-2025:3531expat@2.5.0-3.el9_5.10:2.5.0-3.el9_5.3
MediumRHSA-2025:10407python-setuptools@53.0.0-13.el90:53.0.0-13.el9_6.1
MediumGHSA-9jj7-4m8r-rfcmgithub.com/jackc/pgx/v5@v5.5.55.9.0
MediumRHSA-2026:8510libarchive@3.5.3-4.el90:3.5.3-9.el9_7
MediumGHSA-x527-x647-q7gggolang.org/x/crypto@v0.32.00.52.0
MediumALPINE-CVE-2025-0725curl@8.11.0-r28.12.0-r0
MediumCGA-58rp-89w2-gh83openssl@3.3.2-r03.6.3-r0
MediumRHSA-2025:6977python3.9@3.9.21-1.el9_50:3.9.21-2.el9
MediumGHSA-2xpw-w6gg-jr37urllib3@2.3.02.6.0
MediumGHSA-gm62-xv2j-4w53urllib3@2.3.02.6.0
MediumCGA-3qwq-5w83-3j3qglibc@2.40-r12.43-r7
MediumGHSA-vgwf-h737-ff37golang.org/x/crypto@v0.32.00.52.0
MediumCGA-5mmg-42xf-r978openssl@3.3.2-r03.3.3-r0
MediumCGA-2wwv-w5xp-m9x8openssl@3.3.2-r03.6.3-r0
MediumGHSA-f5wc-c3c7-36mcgolang.org/x/crypto@v0.32.00.52.0
MediumALPINE-CVE-2025-0665curl@8.11.0-r28.12.0-r0
MediumCGA-9w75-pmjm-p5h6openssl@3.3.2-r03.6.3-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.0latest20 days agov0.17.6671446769,355

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/radar-base/kubecost.svg)](https://charts.stackradar.io/charts/radar-base/kubecost)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.