nominatim 6.4.2 Helm chart
robjuzScored 17 Sept 2026
A Helm chart for Kubernetes
Version 6.4.2 yesterdayapp version 5.3.2 2Artifact Hub
nominatim 6.4.2 deploys 4 container images: curlimages/curl, library/nginx, mediagis/nominatim and bitnamilegacy/postgresql. Across them, 825 findings — 1 critical, 2 high. The highest contribution is BIT-postgresql-2025-1094 in postgresql 16.4.0-12, fixed in 13.19.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| curlimages/ | latest | 0000 | 0 |
| library/ | 1.31.6-alpine | 0000 | 0 |
| mediagis/ | 5.3.2 | 0074437 | 5,068 |
| bitnamilegacy/ | 16.4.0-debian-12-r14 | 1266245 | 3,758 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DEBIAN-CVE-2026-54369 | acl | no fix listed |
| Low | DEBIAN-CVE-2017-16231 | pcre3 | no fix listed |
| Low | UBUNTU-CVE-2024-29158 | hdf5 | no fix listed |
| Low | UBUNTU-CVE-2024-29160 | hdf5 | no fix listed |
| Low | UBUNTU-CVE-2024-29162 | hdf5 | no fix listed |
| Low | UBUNTU-CVE-2024-29163 | hdf5 | no fix listed |
| Low | UBUNTU-CVE-2026-7017 | perl | 5.38.2-3.2ubuntu0.4 |
| Low | UBUNTU-CVE-2026-15806 | python3.12 | no fix listed |
| Low | DEBIAN-CVE-2026-54371 | attr | no fix listed |
| Low | DEBIAN-CVE-2025-4598 | systemd | 252.38-1~deb12u1 |
| Low | DEBIAN-CVE-2025-0395 | glibc | 2.36-9+deb12u10 |
| Low | DEBIAN-CVE-2026-77117 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-80489 | glibc | no fix listed |
| Low | DEBIAN-CVE-2023-4039 | gcc-12 | 12.2.0-14+deb12u1 |
| Low | DEBIAN-CVE-2026-86144 | libxml2 | no fix listed |
| Low | DSA-5962-1 | gnutls28 | 3.7.9-2+deb12u5 |
| Low | UBUNTU-CVE-2026-26199 | hdf5 | no fix listed |
| Low | UBUNTU-CVE-2026-6846 | binutils | no fix listed |
| Low | PYSEC-2026-3721 | pip | 26.2 |
| Low | UBUNTU-CVE-2026-13346 | python-pip | no fix listed |
| Low | UBUNTU-CVE-2026-60001 | openssh | 1:9.6p1-3ubuntu13.18 |
| Low | UBUNTU-CVE-2025-12781 | python3.12 | no fix listed |
| Low | DSA-5979-1 | libxslt | 1.1.35-1+deb12u2 |
| Low | UBUNTU-CVE-2025-15366 | python3.12 | no fix listed |
| Low | UBUNTU-CVE-2026-87910 | python3.12 | no fix listed |
| Low | DEBIAN-CVE-2026-22796 | openssl | 3.0.18-1~deb12u2 |
| Low | DEBIAN-CVE-2024-22365 | pam | 1.5.2-6+deb12u2 |
| Low | UBUNTU-CVE-2026-86140 | libxml2 | no fix listed |
| Low | UBUNTU-CVE-2026-47064 | mysql-8.0 | 8.0.46-0ubuntu0.24.04.4 |
| Low | DEBIAN-CVE-2026-86142 | libxml2 | no fix listed |
| Low | DEBIAN-CVE-2022-0563 | util-linux | no fix listed |
| Low | DEBIAN-CVE-2026-4878 | libcap2 | 1:2.66-4+deb12u3 |
| Low | UBUNTU-CVE-2026-11979 | libxml2 | no fix listed |
| Low | BIT-postgresql-2025-12818 | postgresql | 13.23.0 |
| Low | UBUNTU-CVE-2026-19024 | hdf5 | no fix listed |
| Low | UBUNTU-CVE-2025-15367 | python3.12 | no fix listed |
| Low | UBUNTU-CVE-2026-59847 | libssh | 0.10.6-2ubuntu0.5 |
| Low | UBUNTU-CVE-2026-56404 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56410 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56411 | expat | no fix listed |
| Low | DEBIAN-CVE-2026-34743 | xz-utils | 5.4.1-1+deb12u1 |
| Low | DEBIAN-CVE-2026-5704 | tar | no fix listed |
| Low | GHSA-pq67-6m6q-mj2v | urllib3 | 2.5.0 |
| Low | DEBIAN-CVE-2026-3184 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2026-84366 | python3.12 | no fix listed |
| Low | DEBIAN-CVE-2026-7010 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-19487 | perl | 5.38.2-3.2ubuntu0.6 |
| Low | UBUNTU-CVE-2026-82474 | sudo | no fix listed |
| Low | UBUNTU-CVE-2025-2153 | hdf5 | no fix listed |
| Low | GHSA-65pc-fj4g-8rjx | idna | 3.15 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 6.4.2latest | yesterday | 5.3.2 | 12140682 | 8,826 |
| 6.4.1 | 13 days ago | 5.3.2 | 12140686 | 8,860 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.