tbmq-cluster 2.3.1 Helm chart
tbmq-helm-chartOfficialVerified publisherScored 9 Oct 2026
Helm chart for TBMQ cluster (Community and Professional Editions).
Version 2.3.1 todayapp version 2.4.1 5Artifact Hub
tbmq-cluster 2.3.1 deploys 3 container images: thingsboard/tbmq-integration-executor, thingsboard/toolbox and thingsboard/tbmq-node. Across them, 298 findings — 0 critical, 0 high. The highest contribution is DEBIAN-CVE-2019-1010022 in glibc 2.41-12+deb13u4, with no fix listed.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| thingsboard/ | 2.4.1 | 0026109 | 1,452 |
| thingsboard/ | 1.29.0 | 00127 | 171 |
| thingsboard/ | 2.4.1 | 0026109 | 1,452 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DEBIAN-CVE-2026-56391 | coreutils | no fix listed |
| Low | DEBIAN-CVE-2026-18938 | p11-kit | no fix listed |
| Low | DEBIAN-CVE-2026-50813 | sqlite3 | no fix listed |
| Low | DEBIAN-CVE-2017-14159 | openldap | no fix listed |
| Low | DEBIAN-CVE-2017-18018 | coreutils | no fix listed |
| Low | DEBIAN-CVE-2025-10966 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-11850 | krb5 | no fix listed |
| Low | DEBIAN-CVE-2026-75805 | openssl | 3.5.7-1~deb13u3 |
| Low | GHSA-mcr4-qmvw-px4g | lz4-java | 1.11.4 |
| Low | DEBIAN-CVE-2005-2541 | tar | no fix listed |
| Low | DEBIAN-CVE-2026-27171 | zlib | no fix listed |
| Low | DEBIAN-CVE-2026-86805 | glibc | no fix listed |
| Low | DEBIAN-CVE-2025-14017 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-50812 | sqlite3 | no fix listed |
| Low | DEBIAN-CVE-2026-15059 | systemd | no fix listed |
| Low | GHSA-jp4c-xjxw-mgf9 | pip | 26.1 |
| Low | DEBIAN-CVE-2025-5278 | coreutils | no fix listed |
| Low | DEBIAN-CVE-2025-6141 | ncurses | no fix listed |
| Low | DEBIAN-CVE-2026-102473 | dash | no fix listed |
| Low | DEBIAN-CVE-2010-4756 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-42250 | bzip2 | no fix listed |
| Low | DEBIAN-CVE-2024-56433 | shadow | no fix listed |
| Low | DEBIAN-CVE-2026-89092 | glibc | no fix listed |
| Low | DEBIAN-CVE-2011-4116 | perl | no fix listed |
| Low | DEBIAN-CVE-2026-35191 | openssl | 3.5.7-1~deb13u3 |
| Low | GHSA-58qw-9mgm-455v | pip | 26.1 |
| Low | GHSA-343h-94h5-c4wr | lz4-java | 1.11.4 |
| Low | DEBIAN-CVE-2026-16742 | systemd | no fix listed |
| Low | DEBIAN-CVE-2026-18374 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-54875 | openssl | 3.5.7-1~deb13u3 |
| Low | DEBIAN-CVE-2026-22185 | openldap | no fix listed |
| Low | DEBIAN-CVE-2026-97399 | glibc | no fix listed |
| Low | DEBIAN-CVE-2025-15224 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-54872 | openssl | 3.5.7-1~deb13u3 |
| Low | DEBIAN-CVE-2026-77696 | openssl | 3.5.7-1~deb13u3 |
| Low | DEBIAN-CVE-2026-39113 | sqlite3 | no fix listed |
| Low | DEBIAN-CVE-2026-18508 | tar | no fix listed |
| Low | DEBIAN-CVE-2026-102474 | dash | no fix listed |
| Low | DEBIAN-CVE-2007-5686 | shadow | no fix listed |
| Low | DEBIAN-CVE-2026-18477 | tar | no fix listed |
| Low | GO-2026-6599 | stdlib | 1.26.9 |
| Low | GO-2026-6600 | stdlib | 1.26.9 |
| Low | GO-2026-6603 | stdlib | 1.27.2 |
| Low | GO-2026-6603 | golang.org/ | 0.60.0 |
| Low | GO-2026-6604 | stdlib | 1.26.9 |
| Low | GO-2026-6605 | stdlib | 1.26.9 |
| Low | GO-2026-6607 | stdlib | 1.26.9 |
| Low | GO-2026-6608 | stdlib | 1.26.9 |
| Low | GO-2026-6609 | stdlib | 1.26.9 |
| Low | GO-2026-6610 | stdlib | 1.27.2 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.3.1latest | today | 2.4.1 | 0053245 | 3,075 |
| 2.3.0 | 15 days ago | 2.4.0 | 0067291 | 3,961 |
| 2.2.0 | 16 days ago | 2.4.0 | 0067291 | 3,961 |
| 2.1.0 | 1 month ago | 2.4.0 | 1174299 | 4,307 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.