StackRadar

harbor 1.19.2 Helm chart

wenerme

Scored 14 Sept 2026

An open source trusted cloud native registry that stores, signs, and scans content

Version 1.19.2 1 month agoapp version 2.15.2 0Artifact Hub

harbor 1.19.2 deploys 8 container images: goharbor/harbor-core, goharbor/harbor-jobservice, goharbor/harbor-portal, goharbor/registry-photon and 4 more. Across them, 192 findings0 critical, 1 high 1 on CISA KEV. The highest contribution is GO-2026-4919 in github.com/aquasecurity/trivy v0.72.0, with no fix listed.

Radar Score

1,6500120171

192 findings over 8 of 8 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

8 images
ImageTagVulnerabilitiesRadar Score
goharbor/harbor-corev2.15.200031230
goharbor/harbor-jobservicev2.15.200024179
goharbor/harbor-portalv2.15.200000
goharbor/registry-photonv2.15.2001033425
goharbor/harbor-registryctlv2.15.2001038469
goharbor/harbor-db×2v2.15.200000
goharbor/valkey-photonv2.15.200000
goharbor/trivy-adapter-photonv2.15.201045347

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

76 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGO-2026-5158go.opentelemetry.io/otel@v1.43.01.42.0
LowGO-2026-6303golang.org/x/crypto@v0.52.00.55.0
LowGO-2026-6354golang.org/x/crypto@v0.52.00.56.0
LowGO-2026-6091stdlib@go1.26.41.25.13
LowGO-2026-6180golang.org/x/mod@v0.36.00.40.0
LowGO-2026-5694github.com/sigstore/cosign/v2@v2.6.22.6.3
LowGO-2026-5025golang.org/x/net@v0.54.00.55.0
LowGO-2026-4970stdlib@go1.26.41.25.12
LowGO-2022-0635github.com/aws/aws-sdk-go@v1.55.8no fix listed
LowGO-2026-5027golang.org/x/net@v0.54.00.55.0
LowGO-2026-5029golang.org/x/net@v0.54.00.55.0
LowGO-2026-5030golang.org/x/net@v0.54.00.55.0
LowGO-2026-5777github.com/go-chi/chi/v5@v5.2.55.3.0
LowGO-2026-4529github.com/sigstore/cosign/v2@v2.6.2no fix listed
LowGO-2026-5775github.com/go-chi/chi/v5@v5.2.55.3.0
LowGO-2026-6179golang.org/x/mod@v0.36.00.40.0
LowGO-2022-0379github.com/docker/distribution@v0.0.0-20260701071724-493dca9a81a8+dirty2.8.0+incompatible
LowGO-2023-2153google.golang.org/grpc@v0.0.0-20160317175043-d3ddb4469d5a1.56.3
LowGO-2026-5841github.com/klauspost/compress@v1.18.01.18.7
LowGO-2026-5884oras.land/oras-go/v2@v2.6.02.6.1
LowGO-2026-5932golang.org/x/crypto@v0.52.0no fix listed
LowGO-2026-6061google.golang.org/grpc@v1.81.11.82.1
LowGHSA-72x6-4j93-7w86github.com/moby/buildkit@v0.30.00.31.1
LowGHSA-qq97-vm5h-rrhggithub.com/docker/distribution@v0.0.0-20260701071724-493dca9a81a8+dirty2.8.0
LowGHSA-wqqc-jjcq-vfxmgithub.com/sigstore/sigstore-go@v1.1.41.2.1
LowGHSA-xf85-363p-868woras.land/oras-go/v2@v2.6.02.6.1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.19.2latest1 month ago2.15.201201711,650

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/wenerme/harbor.svg)](https://charts.stackradar.io/charts/wenerme/harbor)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.