StackRadar

grocy 0.1.1 Helm chart

sarab97Verified publisher

Scored 14 Sept 2026

grocy is a web-based self-hosted groceries & household management solution for your home

Version 0.1.1 3 years agoapp version 4.0.1 0Artifact Hub

grocy 0.1.1 deploys 1 container image: linuxserver/grocy. Across them, 105 findings8 critical, 10 high 4 on CISA KEV. The highest contribution is ALPINE-CVE-2024-38475 in apache2 2.4.57-r3, fixed in 2.4.60-r0.

Radar Score

2,4498103849

105 findings over 1 of 1 images measured

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
linuxserver/grocy4.0.181038492,449

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

105 distinct across the version’s images
SeverityAdvisoryPackageFixed in
CriticalALPINE-CVE-2024-38475KEVapache2@2.4.57-r32.4.60-r0
CriticalALPINE-CVE-2023-38545curl@8.2.1-r08.4.0-r0
CriticalALPINE-CVE-2023-4863KEVlibwebp@1.3.1-r01.3.1-r1
CriticalALPINE-CVE-2023-44487KEVnghttp2@1.55.1-r01.57.0-r0
CriticalALPINE-CVE-2023-44487KEVnginx@1.24.0-r61.24.0-r7
CriticalALPINE-CVE-2024-38476apache2@2.4.57-r32.4.60-r0
CriticalALPINE-CVE-2024-27316apache2@2.4.57-r32.4.59-r0
CriticalALPINE-CVE-2025-6965sqlite@3.41.2-r23.41.2-r4
HighALPINE-CVE-2023-43622apache2@2.4.57-r32.4.58-r0
HighALPINE-CVE-2024-38472apache2@2.4.57-r32.4.60-r0
HighALPINE-CVE-2024-6119openssl@3.1.2-r03.1.7-r0
HighALPINE-CVE-2023-38039curl@8.2.1-r08.3.0-r0
HighALPINE-CVE-2024-2398curl@8.2.1-r08.7.1-r0
HighALPINE-CVE-2024-32002git@2.40.1-r02.40.3-r0
HighALPINE-CVE-2024-39573apache2@2.4.57-r32.4.60-r0
HighALPINE-CVE-2024-38473apache2@2.4.57-r32.4.60-r0
HighGHSA-r5fr-rjxr-66jclodash@4.17.214.18.0
HighALPINE-CVE-2024-2511openssl@3.1.2-r03.1.4-r6
MediumALPINE-CVE-2024-7264curl@8.2.1-r08.9.1-r0
MediumALPINE-CVE-2024-5535openssl@3.1.2-r03.1.6-r0
MediumALPINE-CVE-2024-38474apache2@2.4.57-r32.4.60-r0
MediumALPINE-CVE-2024-6197curl@8.2.1-r08.9.0-r0
MediumALPINE-CVE-2023-38709apache2@2.4.57-r32.4.59-r0
MediumGHSA-fjxv-7rqg-78g4form-data@2.3.32.5.4
MediumALPINE-CVE-2023-5363openssl@3.1.2-r03.1.4-r0
MediumALPINE-CVE-2024-38477apache2@2.4.57-r32.4.60-r0
MediumALPINE-CVE-2024-45492expat@2.5.0-r12.6.3-r0
MediumALPINE-CVE-2023-31122apache2@2.4.57-r32.4.58-r0
MediumALPINE-CVE-2024-4741openssl@3.1.2-r03.1.6-r0
MediumALPINE-CVE-2024-45491expat@2.5.0-r12.6.3-r0
MediumALPINE-CVE-2024-28757expat@2.5.0-r12.6.2-r0
MediumALPINE-CVE-2023-52425expat@2.5.0-r12.6.0-r0
MediumALPINE-CVE-2024-24795apache2@2.4.57-r32.4.59-r0
MediumALPINE-CVE-2024-45490expat@2.5.0-r12.6.3-r0
MediumGHSA-72xf-g2v4-qvf3tough-cookie@2.5.04.1.3
MediumALPINE-CVE-2023-5678openssl@3.1.2-r03.1.4-r1
MediumALPINE-CVE-2024-40898apache2@2.4.57-r32.4.62-r0
MediumALPINE-CVE-2024-32004git@2.40.1-r02.40.3-r0
MediumALPINE-CVE-2023-6129openssl@3.1.2-r03.1.4-r3
MediumALPINE-CVE-2023-45802apache2@2.4.57-r32.4.58-r0
MediumALPINE-CVE-2024-40725apache2@2.4.57-r32.4.62-r0
MediumALPINE-CVE-2024-8176expat@2.5.0-r12.7.0-r0
MediumALPINE-CVE-2024-9681curl@8.2.1-r08.11.0-r0
MediumALPINE-CVE-2024-0727openssl@3.1.2-r03.1.4-r5
MediumALPINE-CVE-2025-0725curl@8.2.1-r08.12.0-r0
MediumALPINE-CVE-2024-32465git@2.40.1-r02.40.3-r0
MediumALPINE-CVE-2023-7104sqlite@3.41.2-r23.41.2-r3
MediumALPINE-CVE-2023-6237openssl@3.1.2-r03.1.4-r4
MediumALPINE-CVE-2024-9143openssl@3.1.2-r03.1.7-r1
MediumALPINE-CVE-2023-46218curl@8.2.1-r08.5.0-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.1.1latest3 years ago4.0.181038492,449

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/sarab97/grocy.svg)](https://charts.stackradar.io/charts/sarab97/grocy)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.