StackRadar

bookinfo Helm chart

rgnu

Scored 14 Sept 2026

Latest 1.0.0 2 years agoApp version not verified against the render 0Artifact Hub

bookinfo 1.0.0 deploys 7 container images: istio/examples-bookinfo-details-v1, istio/examples-bookinfo-ratings-v1, istio/examples-bookinfo-reviews-v1, istio/examples-bookinfo-reviews-v2 and 3 more. Across them, 1,193 findings13 critical, 46 high. The highest contribution is UBUNTU-CVE-2022-2068 in openssl 1.0.2g-1ubuntu4.14, fixed in 1.0.2g-1ubuntu4.20+esm5.

Radar Score

20,4621346457677

1,193 findings over 7 of 7 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

7 images
ImageTagVulnerabilitiesRadar Score
istio/examples-bookinfo-details-v11.14.0012128807
istio/examples-bookinfo-ratings-v11.14.00359792,364
istio/examples-bookinfo-reviews-v11.14.04121111665,073
istio/examples-bookinfo-reviews-v21.14.04121111665,073
istio/examples-bookinfo-reviews-v31.14.04121111665,073
istio/examples-bookinfo-productpage-v11.14.00137721,528
pstauffer/curllatest1570544

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

529 distinct across the version’s images
SeverityAdvisoryPackageFixed in
CriticalUBUNTU-CVE-2022-2068openssl@1.0.2g-1ubuntu4.141.0.2g-1ubuntu4.20+esm5
CriticalUBUNTU-CVE-2022-1292openssl@1.0.2g-1ubuntu4.141.0.2g-1ubuntu4.20+esm3
CriticalUBUNTU-CVE-2019-8457db5.3@5.3.28-11ubuntu0.15.3.28-11ubuntu0.2
CriticalALPINE-CVE-2019-9513nghttp2@1.32.0-r01.39.2-r0
CriticalUBUNTU-CVE-2024-2961glibc@2.23-0ubuntu102.23-0ubuntu11.3+esm6
HighUBUNTU-CVE-2022-0778openssl@1.0.2g-1ubuntu4.141.0.2g-1ubuntu4.20+esm2
HighGHSA-c4w7-xm78-47vhy18n@4.0.04.0.1
HighALPINE-CVE-2019-9511nghttp2@1.32.0-r01.39.2-r0
HighUBUNTU-CVE-2023-0286openssl@1.0.2g-1ubuntu4.141.0.2g-1ubuntu4.20+esm6
HighGHSA-j544-7q9p-6xp8werkzeug@0.14.10.15.5
HighUBUNTU-CVE-2018-25032zlib@1:1.2.8.dfsg-2ubuntu4.11:1.2.8.dfsg-2ubuntu4.3+esm1
HighUBUNTU-CVE-2021-23840openssl@1.0.2g-1ubuntu4.141.0.2g-1ubuntu4.19
HighUBUNTU-CVE-2023-2650openssl@1.0.2g-1ubuntu4.141.0.2g-1ubuntu4.20+esm9
HighUBUNTU-CVE-2021-3712openssl@1.0.2g-1ubuntu4.141.0.2g-1ubuntu4.20+esm1
HighALPINE-CVE-2019-5482curl@7.60.0-r17.61.1-r3
HighUBUNTU-CVE-2022-37434zlib@1:1.2.8.dfsg-2ubuntu4.11:1.2.8.dfsg-2ubuntu4.3+esm2
HighUBUNTU-CVE-2018-1000035unzip@6.0-20ubuntu16.0-20ubuntu1.1
HighALPINE-CVE-2019-3822curl@7.60.0-r17.61.1-r2
HighUBUNTU-CVE-2024-2511openssl@1.0.2g-1ubuntu4.141.0.2g-1ubuntu4.20+esm18
HighALPINE-CVE-2018-14618curl@7.60.0-r17.61.1-r0
HighGHSA-w573-4hg7-7wgqdecode-uri-component@0.2.00.2.1
HighGHSA-3jfq-g458-7qm9tar@2.2.13.2.2
HighGHSA-jvgm-pfqv-887xbundler@1.17.22.0.0
HighUBUNTU-CVE-2019-12900bzip2@1.0.6-81.0.6-8ubuntu0.1
HighUBUNTU-CVE-2016-9841zlib@1:1.2.8.dfsg-2ubuntu4.11:1.2.8.dfsg-2ubuntu4.3
HighALPINE-CVE-2019-5481curl@7.60.0-r17.61.1-r3
HighUBUNTU-CVE-2018-11236glibc@2.23-0ubuntu102.23-0ubuntu11.2
MediumGHSA-hrpp-h998-j3ppqs@6.5.26.5.3
MediumUBUNTU-CVE-2020-10543perl@5.22.1-9ubuntu0.65.22.1-9ubuntu0.9
MediumALPINE-CVE-2018-0500curl@7.60.0-r17.61.0-r0
MediumUBUNTU-CVE-2019-5953wget@1.17.1-1ubuntu1.41.17.1-1ubuntu1.5
MediumALPINE-CVE-2018-16839curl@7.60.0-r17.61.1-r1
MediumUBUNTU-CVE-2016-9843zlib@1:1.2.8.dfsg-2ubuntu4.11:1.2.8.dfsg-2ubuntu4.3
MediumDLA-2544-1openldap@2.4.44+dfsg-5+deb9u22.4.44+dfsg-5+deb9u7
MediumDSA-4511-1nghttp2@1.18.1-11.18.1-1+deb9u1
MediumDLA-2952-1openssl@1.1.0j-1~deb9u11.1.0l-1~deb9u5
MediumDLA-2953-1openssl1.0@1.0.2r-1~deb9u11.0.2u-1~deb9u7
MediumUBUNTU-CVE-2017-10684ncurses@6.0+20160213-1ubuntu16.0+20160213-1ubuntu1+esm1
MediumUBUNTU-CVE-2019-9169glibc@2.23-0ubuntu102.23-0ubuntu11.2
MediumUBUNTU-CVE-2022-23218glibc@2.23-0ubuntu102.23-0ubuntu11.3+esm1
MediumUBUNTU-CVE-2017-18269glibc@2.23-0ubuntu102.23-0ubuntu11.2
MediumUBUNTU-CVE-2018-6485glibc@2.23-0ubuntu102.23-0ubuntu11.2
MediumGHSA-2p57-rm9w-gvfpip@1.1.5no fix listed
MediumGHSA-xvch-5gv4-984hminimist@1.2.01.2.6
MediumGHSA-fp4w-jxhp-m23pbundler@1.17.22.2.10
MediumGHSA-r628-mhmh-qjhwtar@4.4.84.4.15
MediumUBUNTU-CVE-2016-3189bzip2@1.0.6-81.0.6-8ubuntu0.1
MediumUBUNTU-CVE-2024-5535openssl@1.0.2g-1ubuntu4.141.0.2g-1ubuntu4.20+esm18
MediumDLA-3017-1openldap@2.4.44+dfsg-5+deb9u22.4.44+dfsg-5+deb9u9
MediumDLA-2574-1openldap@2.4.44+dfsg-5+deb9u22.4.44+dfsg-5+deb9u8

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.0latest2 years ago134645767720,462

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/rgnu/bookinfo.svg)](https://charts.stackradar.io/charts/rgnu/bookinfo)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.