StackRadar

zipkin 2.1.4 Helm chart

ygqygq2Verified publisher

Scored 14 Sept 2026

Zipkin is a distributed tracing system.

Version 2.1.4 3 years agoapp version 2.24 4Artifact Hub

zipkin 2.1.4 deploys 4 container images: openzipkin/zipkin, bitnami/bitnami-shell, bitnami/elasticsearch and openzipkin/zipkin-dependencies. Across the 2 measured, 158 findings1 critical, 11 high. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

2,7641114798

158 findings over 2 of 4 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

4 images
ImageTagVulnerabilitiesRadar Score
openzipkin/zipkin2.240323891,485
bitnami/bitnami-shell×310-debian-10-r403unmeasured
bitnami/elasticsearch×37.17.3-debian-10-r0unmeasured
openzipkin/zipkin-dependencies2.6.4182491,279

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

158 distinct across the version’s images
SeverityAdvisoryPackageFixed in
CriticalALPINE-CVE-2021-3711openssl@1.1.1g-r01.1.1l-r0
HighALPINE-CVE-2022-25236expat@2.2.10-r02.2.10-r2
HighALPINE-CVE-2022-0778openssl@1.1.1g-r01.1.1n-r0
HighGHSA-vgq5-3255-v292kafka-clients@3.6.03.9.1
HighALPINE-CVE-2024-6119openssl@3.1.4-r23.1.7-r0
HighALPINE-CVE-2018-25032zlib@1.2.11-r31.2.12-r0
HighALPINE-CVE-2021-23840openssl@1.1.1g-r01.1.1j-r0
HighALPINE-CVE-2021-3712openssl@1.1.1g-r01.1.1l-r0
HighALPINE-CVE-2022-37434zlib@1.2.11-r31.2.12-r2
HighALPINE-CVE-2021-43527nss@3.60-r03.60-r2
HighALPINE-CVE-2021-3449openssl@1.1.1g-r01.1.1k-r0
HighALPINE-CVE-2024-2511openssl@3.1.4-r23.1.4-r6
MediumALPINE-CVE-2022-25235expat@2.2.10-r02.2.10-r2
MediumALPINE-CVE-2022-25315expat@2.2.10-r02.2.10-r2
MediumALPINE-CVE-2021-36222krb5@1.18.3-r11.18.4-r0
MediumALPINE-CVE-2022-23852expat@2.2.10-r02.2.10-r1
MediumALPINE-CVE-2024-5535openssl@3.1.4-r23.1.6-r0
MediumGHSA-whxr-3p84-rf3cactivemq-client@5.18.35.18.7
MediumALPINE-CVE-2022-27404freetype@2.10.4-r02.10.4-r1
MediumALPINE-CVE-2022-28391busybox@1.31.1-r191.31.1-r22
MediumALPINE-CVE-2021-36159apk-tools@2.10.5-r12.10.7-r0
MediumALPINE-CVE-2022-25314expat@2.2.10-r02.2.10-r2
MediumALPINE-CVE-2022-23990expat@2.2.10-r02.2.10-r1
MediumALPINE-CVE-2021-23841openssl@1.1.1g-r01.1.1j-r0
MediumALPINE-CVE-2020-1971openssl@1.1.1g-r01.1.1i-r0
MediumALPINE-CVE-2022-27406freetype@2.10.4-r02.10.4-r2
MediumALPINE-CVE-2024-4741openssl@3.1.4-r23.1.6-r0
MediumALPINE-CVE-2022-27405freetype@2.10.4-r02.10.4-r2
MediumALPINE-CVE-2021-42380busybox@1.31.1-r191.31.1-r21
MediumALPINE-CVE-2021-42379busybox@1.31.1-r191.31.1-r21
MediumALPINE-CVE-2021-42381busybox@1.31.1-r191.31.1-r21
MediumALPINE-CVE-2021-42385busybox@1.31.1-r191.31.1-r21
MediumALPINE-CVE-2021-42378busybox@1.31.1-r191.31.1-r21
MediumALPINE-CVE-2021-42382busybox@1.31.1-r191.31.1-r21
MediumALPINE-CVE-2021-42384busybox@1.31.1-r191.31.1-r21
MediumALPINE-CVE-2021-42386busybox@1.31.1-r191.31.1-r21
MediumGHSA-4g8c-wm8x-jfhwnetty-handler@4.1.100.Final4.1.118.Final
MediumALPINE-CVE-2022-25313expat@2.2.10-r02.2.10-r2
MediumALPINE-CVE-2021-42383busybox@1.31.1-r191.31.1-r21
MediumGHSA-w9fj-cfpg-grvvnetty-codec-http2@4.1.100.Final4.1.132.Final
MediumALPINE-CVE-2025-9230openssl@3.1.4-r23.1.8-r1
MediumALPINE-CVE-2023-6129openssl@3.1.4-r23.1.4-r3
MediumALPINE-CVE-2021-37750krb5@1.18.3-r11.18.5-r0
MediumGHSA-3qp7-7mw8-wx86netty-handler@4.1.100.Final4.1.135.Final
MediumALPINE-CVE-2024-0727openssl@3.1.4-r23.1.4-r5
MediumGHSA-rmj7-2vxq-3g9fjackson-databind@2.16.02.18.8
MediumALPINE-CVE-2023-6237openssl@3.1.4-r23.1.4-r4
MediumALPINE-CVE-2024-9143openssl@3.1.4-r23.1.7-r1
MediumGHSA-j3rv-43j4-c7qmjackson-databind@2.16.02.18.8
MediumGHSA-prj3-ccx8-p6x4netty-codec-http2@4.1.100.Final4.1.124.Final

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.1.4latest3 years ago2.2411147982,764

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/ygqygq2/zipkin.svg)](https://charts.stackradar.io/charts/ygqygq2/zipkin)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.