wazuh 2.0.7 Helm chart
wazuh-helm-morgovedVerified publisherScored 15 Sept 2026
Wazuh is a free and open source security platform that unifies XDR and SIEM protection for endpoints and cloud workloads.
Version 2.0.7 3 days agoapp version 4.14.3 11Artifact Hub
wazuh 2.0.7 deploys 5 container images: kinseii/wazuh-agent, wazuh/wazuh-dashboard, wazuh/wazuh-indexer, library/alpine and 1 more. Across them, 1,010 findings — 3 critical, 8 high — 2 on CISA KEV. The highest contribution is DEBIAN-CVE-2023-50387 in systemd 252.22-1~deb12u1, fixed in 252.23-1~deb12u1.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| kinseii/ | 4.14.1 | 3189413 | 5,679 |
| wazuh/ | 4.14.3 | 0221131 | 1,776 |
| wazuh/ | 4.14.3 | 001248 | 718 |
| library/ | latest | 0046 | 149 |
| wazuh/ | 4.14.3 | 0540234 | 3,080 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2023-1569 | stdlib | 1.19.6 |
| Low | DEBIAN-CVE-2025-12781 | python3.11 | no fix listed |
| Low | DEBIAN-CVE-2026-27447 | cups | no fix listed |
| Low | GHSA-mq26-g339-26xf | pip | 23.3 |
| Low | DEBIAN-CVE-2025-15366 | python3.11 | no fix listed |
| Low | DEBIAN-CVE-2026-87910 | python3.11 | no fix listed |
| Low | GHSA-cpwx-vrp4-4pq7 | jinja2 | 3.1.6 |
| Low | GHSA-q7cg-457f-vx79 | joi | 17.13.4 |
| Low | GHSA-crv5-9vww-q3g8 | dompurify | 3.4.0 |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | GO-2023-2382 | stdlib | 1.20.12 |
| Low | DEBIAN-CVE-2026-6429 | curl | no fix listed |
| Low | GHSA-v2wj-7wpq-c8vv | dompurify | 3.3.2 |
| Low | GO-2022-1143 | stdlib | 1.18.9 |
| Low | GHSA-22g5-r2x5-97cx | showdown | no fix listed |
| Low | GHSA-qpw4-5x99-6vjp | golang.org/ | 0.52.0 |
| Low | DEBIAN-CVE-2024-22365 | pam | 1.5.2-6+deb12u2 |
| Low | GHSA-c69g-56f8-xwqj | netty-codec-http2 | 4.1.136.Final |
| Low | DEBIAN-CVE-2026-22796 | openssl | 3.0.18-1~deb12u2 |
| Low | GHSA-f6x5-jh6r-wrfv | golang.org/ | 0.45.0 |
| Low | GHSA-gvwx-54wh-qm9j | tar | 7.5.17 |
| Low | GHSA-78mq-xcr3-xm33 | golang.org/ | 0.52.0 |
| Low | GO-2024-2599 | stdlib | 1.21.8 |
| Low | DEBIAN-CVE-2025-10148 | curl | 7.88.1-10+deb12u15 |
| Low | GHSA-cr32-g25g-vxjj | showdown | no fix listed |
| Low | GHSA-v9jr-rg53-9pgp | dompurify | 3.4.0 |
| Low | GO-2022-1038 | stdlib | 1.18.7 |
| Low | DEBIAN-CVE-2026-22695 | libpng1.6 | 1.6.39-2+deb12u2 |
| Low | GHSA-27v5-c462-wpq7 | path-to-regexp | 8.4.0 |
| Low | GO-2024-3106 | stdlib | 1.22.7 |
| Low | DEBIAN-CVE-2026-24401 | avahi | no fix listed |
| Low | GHSA-87hc-h4r5-73f7 | werkzeug | 3.1.5 |
| Low | GHSA-hjcp-jmpx-g3qm | httpclient5 | 5.6.3 |
| Low | DEBIAN-CVE-2026-1965 | curl | no fix listed |
| Low | GO-2023-1570 | stdlib | 1.19.6 |
| Low | DEBIAN-CVE-2022-0563 | util-linux | no fix listed |
| Low | DEBIAN-CVE-2026-4878 | libcap2 | 1:2.66-4+deb12u3 |
| Low | DEBIAN-CVE-2026-11979 | libxml2 | no fix listed |
| Low | DEBIAN-CVE-2026-7168 | curl | 7.88.1-10+deb12u15 |
| Low | GHSA-v2v4-37r5-5v8g | ip-address | 10.1.1 |
| Low | DEBIAN-CVE-2026-86140 | libxml2 | no fix listed |
| Low | GHSA-378v-28hj-76wf | bn.js | 5.2.3 |
| Low | GO-2022-0531 | stdlib | 1.17.11 |
| Low | GO-2024-2600 | stdlib | 1.21.8 |
| Low | DEBIAN-CVE-2025-15367 | python3.11 | no fix listed |
| Low | GHSA-hrxh-6v49-42gf | google.golang.org/ | 1.82.1 |
| Low | GHSA-38f8-5428-x5cv | netty-codec-http | 4.1.133.Final |
| Low | GHSA-h8r8-wccr-v5f2 | dompurify | 3.3.2 |
| Low | GHSA-h7mw-gpvr-xq4m | dompurify | 3.4.0 |
| Low | DEBIAN-CVE-2026-3783 | curl | 7.88.1-10+deb12u15 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.0.7latest | 3 days ago | 4.14.3 | 38166832 | 11,402 |
| 2.0.5 | 12 days ago | 4.14.3 | 38166832 | 11,402 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.