tyk-data-plane 5.4.0 Helm chart
tyk-helmScored 24 Sept 2026
A Helm chart for deploying a Tyk data plane for Tyk Self Managed MDCB or Tyk Cloud users. It will deploy the data plane components that remotely connect to a MDCB control plane. It includes the Tyk Gateway, an open source Enterprise API Gateway, supporting REST, GraphQL, TCP and gRPC protocols; and Tyk Pump, an analytics purger that moves the data generated by your Tyk gateways to any back-end. Furthermore, it has all the required modifications to easily connect to Tyk Cloud or Multi Data Center (MDCB) control plane.
Version 5.4.0 todayApp version not verified against the render 0Artifact Hub
tyk-data-plane 5.4.0 deploys 3 container images: library/busybox, tykio/tyk-gateway-ee and tykio/tyk-pump-docker-pub. Across them, 66 findings — 0 critical, 0 high. The highest contribution is DEBIAN-CVE-2019-1010022 in glibc 2.41-12+deb13u3+dhi1, with no fix listed.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 1.32 | 0000 | 0 |
| tykio/ | v5.13.2 | 001049 | 628 |
| tykio/ | v1.17.0 | 0007 | 58 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-j497-x9hr-x34x | github.com/ | 1.13.0 |
| Low | GHSA-4v58-74mf-rjx3 | github.com/ | 1.13.0 |
| Low | GHSA-r9c8-gcjp-xfwh | github.com/ | 1.13.0 |
| Low | GHSA-xwwf-m8fg-p9q2 | github.com/ | 1.13.0 |
| Low | GHSA-2v4p-qf9q-27wj | google.golang.org/ | 1.82.2 |
| Low | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Low | GHSA-8wv5-x4w7-5gww | github.com/ | 0.24.0 |
| Low | DEBIAN-CVE-2026-85091 | zlib | no fix listed |
| Low | DEBIAN-CVE-2026-26157 | busybox | no fix listed |
| Low | GHSA-rm6m-hrcw-jw33 | github.com/ | 1.13.0 |
| Low | GHSA-6c5v-hqjr-5xxp | github.com/ | 1.13.0 |
| Low | GHSA-33mj-cw25-m34h | github.com/ | 1.13.0 |
| Low | DEBIAN-CVE-2026-19499 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-5928 | glibc | 2.41-12+deb13u4 |
| Low | DEBIAN-CVE-2026-6791 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-29004 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-6238 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-5435 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-77117 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-80489 | glibc | no fix listed |
| Low | DEBIAN-CVE-2025-60876 | busybox | no fix listed |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | DEBIAN-CVE-2023-42366 | busybox | no fix listed |
| Low | GHSA-465g-fh3v-9jw4 | github.com/ | 1.13.0 |
| Low | DEBIAN-CVE-2026-26158 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-38754 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-19542 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-8674 | glibc | no fix listed |
| Low | GHSA-27gv-rfvv-22mv | github.com/ | 1.13.0 |
| Low | DEBIAN-CVE-2026-27171 | zlib | no fix listed |
| Low | DEBIAN-CVE-2026-86805 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-38753 | busybox | no fix listed |
| Low | GO-2026-6355 | golang.org/ | 0.56.0 |
| Low | DEBIAN-CVE-2010-4756 | glibc | no fix listed |
| Low | GO-2026-6354 | golang.org/ | 0.56.0 |
| Low | DEBIAN-CVE-2026-89092 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-18374 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-76014 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-38752 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-38755 | busybox | no fix listed |
| Low | DEBIAN-CVE-2025-46394 | busybox | no fix listed |
| Low | GO-2026-5841 | github.com/ | 1.18.7 |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | DEBIAN-CVE-2026-95818 | glibc | no fix listed |
| Low | DEBIAN-CVE-2024-58251 | busybox | no fix listed |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
| Low | DEBIAN-CVE-2026-6368 | glibc | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 5.4.0latest | today | — | 001056 | 686 |
| 5.3.0 | 2 months ago | — | 001494 | 1,020 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.