StackRadar

velero 12.2.1 Helm chart

vmware-tanzu

Scored 9 Oct 2026

A Helm chart for velero

Version 12.2.1 yesterdayapp version 1.18.2 191Artifact Hub

velero 12.2.1 deploys 1 container image: velero/velero. Across them, 113 findings — 1 critical, 2 high. The highest contribution is UBUNTU-CVE-2025-15467 in openssl 3.0.2-0ubuntu1.25, with no fix listed. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.

Radar Score

1,393122882

113 findings over 1 of 1 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
velero/velero×2v1.18.21228821,393

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

82 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2026-31789openssl@3.0.2-0ubuntu1.25no fix listed
LowUBUNTU-CVE-2026-45445openssl@3.0.2-0ubuntu1.25no fix listed
LowUBUNTU-CVE-2026-4046glibc@2.35-0ubuntu3.132.35-0ubuntu3.14
LowGO-2026-5942golang.org/x/net@v0.55.00.56.0
LowUBUNTU-CVE-2026-54874openssl@3.0.2-0ubuntu1.253.0.2-0ubuntu1.29
LowUBUNTU-CVE-2025-69419openssl@3.0.2-0ubuntu1.25no fix listed
LowGO-2026-5972stdlib@go1.25.111.25.13
LowGO-2026-6088stdlib@go1.25.111.25.13
LowGO-2026-6089stdlib@go1.25.111.25.13
LowGO-2026-6090stdlib@go1.25.111.25.13
LowGO-2026-6218stdlib@go1.25.111.25.13
LowUBUNTU-CVE-2026-42766openssl@3.0.2-0ubuntu1.25no fix listed
LowUBUNTU-CVE-2026-84782openssl@3.0.2-0ubuntu1.253.0.2-0ubuntu1.30
LowGO-2026-6355golang.org/x/crypto@v0.52.00.56.0
LowUBUNTU-CVE-2026-5928glibc@2.35-0ubuntu3.132.35-0ubuntu3.14
LowGO-2026-5970golang.org/x/text@v0.37.00.39.0
LowGO-2026-6303golang.org/x/crypto@v0.52.00.55.0
LowGO-2026-6354golang.org/x/crypto@v0.52.00.56.0
LowUBUNTU-CVE-2026-75803openssl@3.0.2-0ubuntu1.253.0.2-0ubuntu1.29
LowUBUNTU-CVE-2024-4603openssl@3.0.2-0ubuntu1.25no fix listed
LowUBUNTU-CVE-2026-95619gcc-12@12.3.0-1ubuntu1~22.04.3no fix listed
LowUBUNTU-CVE-2026-6791glibc@2.35-0ubuntu3.132.35-0ubuntu3.15
LowGO-2026-5841github.com/klauspost/compress@v1.18.21.18.7
LowUBUNTU-CVE-2026-5435glibc@2.35-0ubuntu3.132.35-0ubuntu3.14
LowUBUNTU-CVE-2022-27943gcc-12@12.3.0-1ubuntu1~22.04.3no fix listed
LowUBUNTU-CVE-2026-85091zlib@1:1.2.11.dfsg-2ubuntu9.2no fix listed
LowGO-2026-6180golang.org/x/mod@v0.36.00.40.0
LowUBUNTU-CVE-2026-6238glibc@2.35-0ubuntu3.132.35-0ubuntu3.14
LowUBUNTU-CVE-2026-63074openssl@3.0.2-0ubuntu1.253.0.2-0ubuntu1.29
LowGO-2026-4970stdlib@go1.25.111.25.12
LowUBUNTU-CVE-2026-42767openssl@3.0.2-0ubuntu1.25no fix listed
LowUBUNTU-CVE-2026-22796openssl@3.0.2-0ubuntu1.25no fix listed
LowUBUNTU-CVE-2026-102010gcc-12@12.3.0-1ubuntu1~22.04.3no fix listed
LowUBUNTU-CVE-2026-77117glibc@2.35-0ubuntu3.132.35-0ubuntu3.15
LowUBUNTU-CVE-2026-80489glibc@2.35-0ubuntu3.132.35-0ubuntu3.15
LowGHSA-qc2q-p7wx-3px3google.golang.org/grpc@v1.81.11.83.1
LowGO-2026-6179golang.org/x/mod@v0.36.00.40.0
LowGO-2026-6091stdlib@go1.25.111.25.13
LowGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc@v1.81.11.82.1
LowUBUNTU-CVE-2026-75806openssl@3.0.2-0ubuntu1.253.0.2-0ubuntu1.30
LowGO-2026-5856stdlib@go1.25.111.25.12
LowUBUNTU-CVE-2026-8674glibc@2.35-0ubuntu3.13no fix listed
LowGO-2026-5158go.opentelemetry.io/otel@v1.43.01.42.0
LowUBUNTU-CVE-2024-13176openssl@3.0.2-0ubuntu1.25no fix listed
LowUBUNTU-CVE-2026-35189openssl@3.0.2-0ubuntu1.253.0.2-0ubuntu1.30
LowUBUNTU-CVE-2026-19542glibc@2.35-0ubuntu3.132.35-0ubuntu3.15
LowUBUNTU-CVE-2026-75805openssl@3.0.2-0ubuntu1.253.0.2-0ubuntu1.30
LowUBUNTU-CVE-2026-86805glibc@2.35-0ubuntu3.13no fix listed
LowUBUNTU-CVE-2026-22795openssl@3.0.2-0ubuntu1.25no fix listed
LowUBUNTU-CVE-2026-45446openssl@3.0.2-0ubuntu1.25no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
12.2.1latestyesterday1.18.21228821,393
12.2.023 days ago1.18.21228821,393
12.1.03 months ago1.18.10328761,347

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/vmware-tanzu/velero.svg)](https://charts.stackradar.io/charts/vmware-tanzu/velero)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 9 Oct 2026 · scanned 9 Oct 2026 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.