StackRadar

nominatim 6.4.2 Helm chart

robjuz

Scored 17 Sept 2026

A Helm chart for Kubernetes

Version 6.4.2 yesterdayapp version 5.3.2 2Artifact Hub

nominatim 6.4.2 deploys 4 container images: curlimages/curl, library/nginx, mediagis/nominatim and bitnamilegacy/postgresql. Across them, 825 findings1 critical, 2 high. The highest contribution is BIT-postgresql-2025-1094 in postgresql 16.4.0-12, fixed in 13.19.0.

Radar Score

8,82612140682

825 findings over 4 of 4 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

4 images
ImageTagVulnerabilitiesRadar Score
curlimages/curllatest00000
library/nginx1.31.6-alpine00000
mediagis/nominatim×25.3.200744375,068
bitnamilegacy/postgresql16.4.0-debian-12-r1412662453,758

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

717 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumUBUNTU-CVE-2019-6988openjpeg2@2.5.0-2ubuntu0.5no fix listed
MediumUBUNTU-CVE-2026-5450glibc@2.39-0ubuntu8.72.39-0ubuntu8.8
MediumDEBIAN-CVE-2024-9143openssl@3.0.14-1~deb12u23.0.15-1~deb12u1
MediumBIT-postgresql-2026-14669postgresql@16.4.0-1214.24.0
MediumUBUNTU-CVE-2026-14669postgresql-16@16.14-0ubuntu0.24.04.116.15-0ubuntu0.24.04.1
MediumDEBIAN-CVE-2026-34182openssl@3.0.14-1~deb12u23.0.20-1~deb12u2
MediumUBUNTU-CVE-2018-13875hdf5@1.10.10+repack-3.1ubuntu4no fix listed
MediumDEBIAN-CVE-2025-27113libxml2@2.9.14+dfsg-1.3~deb12u12.9.14+dfsg-1.3~deb12u2
MediumPYSEC-2024-230certifi@2023.11.172024.7.4
MediumDEBIAN-CVE-2026-31790openssl@3.0.14-1~deb12u23.0.19-1~deb12u2
MediumDEBIAN-CVE-2025-32990gnutls28@3.7.9-2+deb12u33.7.9-2+deb12u5
MediumDEBIAN-CVE-2026-34180openssl@3.0.14-1~deb12u23.0.20-1~deb12u2
MediumDEBIAN-CVE-2025-31115xz-utils@5.4.1-0.25.4.1-1
MediumDEBIAN-CVE-2026-7383openssl@3.0.14-1~deb12u23.0.20-1~deb12u2
MediumUBUNTU-CVE-2025-69720ncurses@6.4+20240113-1ubuntu26.4+20240113-1ubuntu2.1
MediumUBUNTU-CVE-2026-8376perl@5.38.2-3.2ubuntu0.25.38.2-3.2ubuntu0.3
MediumDEBIAN-CVE-2025-9232openssl@3.0.14-1~deb12u23.0.17-1~deb12u3
MediumUBUNTU-CVE-2026-5260gnutls28@3.8.3-1.1ubuntu3.53.8.3-1.1ubuntu3.6
MediumDEBIAN-CVE-2025-69421openssl@3.0.14-1~deb12u23.0.18-1~deb12u2
MediumUBUNTU-CVE-2026-8927curl@8.5.0-2ubuntu10.98.5.0-2ubuntu10.10
MediumUBUNTU-CVE-2026-9669python3.12@3.12.3-1ubuntu0.133.12.3-1ubuntu0.15
MediumDEBIAN-CVE-2026-28388openssl@3.0.14-1~deb12u23.0.19-1~deb12u2
MediumUBUNTU-CVE-2019-8396hdf5@1.10.10+repack-3.1ubuntu4no fix listed
MediumUBUNTU-CVE-2018-17432hdf5@1.10.10+repack-3.1ubuntu4no fix listed
MediumBIT-postgresql-2026-16239postgresql@16.4.0-1214.24.0
MediumUBUNTU-CVE-2026-16239postgresql-16@16.14-0ubuntu0.24.04.116.15-0ubuntu0.24.04.1
MediumDEBIAN-CVE-2026-28387openssl@3.0.14-1~deb12u23.0.19-1~deb12u2
MediumDEBIAN-CVE-2015-9019libxslt@1.1.35-1no fix listed
MediumUBUNTU-CVE-2026-11940python3.12@3.12.3-1ubuntu0.13no fix listed
MediumUBUNTU-CVE-2018-17439hdf5@1.10.10+repack-3.1ubuntu4no fix listed
MediumDEBIAN-CVE-2025-69420openssl@3.0.14-1~deb12u23.0.18-1~deb12u2
MediumUBUNTU-CVE-2026-26740giflib@5.2.2-1ubuntu15.2.2-1ubuntu1.2
MediumDEBIAN-CVE-2026-28389openssl@3.0.14-1~deb12u23.0.19-1~deb12u2
MediumDEBIAN-CVE-2026-28390openssl@3.0.14-1~deb12u23.0.19-1~deb12u2
MediumDEBIAN-CVE-2019-1010025glibc@2.36-9+deb12u8no fix listed
LowUBUNTU-CVE-2026-57433perl@5.38.2-3.2ubuntu0.25.38.2-3.2ubuntu0.4
LowUBUNTU-CVE-2024-32609hdf5@1.10.10+repack-3.1ubuntu4no fix listed
LowDEBIAN-CVE-2026-6653libxml2@2.9.14+dfsg-1.3~deb12u1no fix listed
LowUBUNTU-CVE-2019-8398hdf5@1.10.10+repack-3.1ubuntu4no fix listed
LowUBUNTU-CVE-2019-8397hdf5@1.10.10+repack-3.1ubuntu4no fix listed
LowUBUNTU-CVE-2026-13221perl@5.38.2-3.2ubuntu0.25.38.2-3.2ubuntu0.4
LowUBUNTU-CVE-2026-42496perl@5.38.2-3.2ubuntu0.25.38.2-3.2ubuntu0.3
LowDEBIAN-CVE-2024-56406perl@5.36.0-7+deb12u15.36.0-7+deb12u2
LowUBUNTU-CVE-2017-17507hdf5@1.10.10+repack-3.1ubuntu4no fix listed
LowBIT-postgresql-2026-14662postgresql@16.4.0-1214.24.0
LowUBUNTU-CVE-2026-14662postgresql-16@16.14-0ubuntu0.24.04.116.15-0ubuntu0.24.04.1
LowUBUNTU-CVE-2025-44905hdf5@1.10.10+repack-3.1ubuntu4no fix listed
LowUBUNTU-CVE-2026-6100python3.12@3.12.3-1ubuntu0.133.12.3-1ubuntu0.15
LowBIT-postgresql-2026-6478postgresql@16.4.0-1214.23.0
LowUBUNTU-CVE-2026-73515postgis@3.4.2+dfsg-1ubuntu3no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
6.4.2latestyesterday5.3.2121406828,826
6.4.112 days ago5.3.2121406868,860

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/robjuz/nominatim.svg)](https://charts.stackradar.io/charts/robjuz/nominatim)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 17 Sept 2026 · scanned 17 Sept 2026 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.