StackRadar

gollum 3.4.2 Helm chart

geek-cookbookVerified publisher

Scored 14 Sept 2026

Gollum is a simple wiki system built on top of Git

Version 3.4.2 4 years agoapp version latest 1Artifact Hub

gollum 3.4.2 deploys 3 container images: library/alpine, alpine/git and gollumorg/gollum. Across them, 324 findings0 critical, 6 high 2 on CISA KEV. The highest contribution is GHSA-jc36-42cf-vqwj in nokogiri 1.10.10, fixed in 1.13.4. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.

Radar Score

4,6290691227

324 findings over 3 of 3 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
library/alpinelatest0046149
alpine/git×2latest02950680
gollumorg/gollumlatest04781713,800

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

221 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-7g2v-jj9q-g3rgrack@2.2.32.2.11
LowDLA-3614-1python3.7@3.7.3-2+deb10u23.7.3-2+deb10u6
LowDSA-5122-1gzip@1.9-31.9-3+deb10u1
LowDSA-5123-1xz-utils@5.2.4-15.2.4-1+deb10u1
LowDSA-4882-1openjpeg2@2.3.0-2+deb10u12.3.0-2+deb10u2
LowDSA-5073-1expat@2.2.6-2+deb10u12.2.6-2+deb10u2
LowALPINE-CVE-2026-14456openssl@3.5.7-r03.5.8-r0
LowGHSA-vg3r-rm7w-2xghrexml@3.2.33.2.7
LowALPINE-CVE-2026-82209curl@8.21.0-r08.22.0-r0
LowGHSA-mq66-vcfc-8246mercurial@4.8.24.9
LowALPINE-CVE-2026-80255curl@8.21.0-r08.22.0-r0
LowGHSA-h8w8-99g7-qmvjconcurrent-ruby@1.1.71.3.7
LowGHSA-mxw3-3hh2-x2mhrack@2.2.32.2.22
LowDLA-3288-1curl@7.64.0-4+deb10u17.64.0-4+deb10u4
LowDLA-3651-1postgresql-11@11.9-0+deb10u111.22-0+deb10u1
LowGHSA-6xw4-3v39-52mmrack@2.2.32.2.20
LowDSA-5087-1cyrus-sasl2@2.1.27+dfsg-1+deb10u12.1.27+dfsg-1+deb10u2
LowALPINE-CVE-2026-13608curl@8.21.0-r08.22.0-r0
LowALPINE-CVE-2026-63072openssl@3.5.7-r03.5.8-r0
LowGHSA-hww2-5g85-429muri@0.10.00.10.0.3
LowALPINE-CVE-2026-60002openssh@10.3_p1-r010.3_p1-r1
LowGHSA-vmwr-mc7x-5vc3rexml@3.2.33.3.6
LowGHSA-8cgq-6mh2-7j6vrack@2.2.32.2.12
LowGHSA-625h-95r8-8xpmrack@2.2.32.2.18
LowDSA-5142-1libxml2@2.9.4+dfsg1-7+deb10u12.9.4+dfsg1-7+deb10u4
LowGHSA-j4pr-3wm6-xx2ruri@0.10.00.12.5
LowALPINE-CVE-2026-80230curl@8.21.0-r08.22.0-r0
LowGHSA-w9pc-fmgc-vxvwrack@2.2.32.2.19
LowDSA-5032-1djvulibre@3.5.27.1-103.5.27.1-10+deb10u1
LowALPINE-CVE-2026-76641expat@2.8.3-r02.8.4-r0
LowDSA-4822-1p11-kit@0.23.15-20.23.15-2+deb10u1
LowALPINE-CVE-2026-54874openssl@3.5.7-r03.5.8-r0
LowDLA-3363-1pcre2@10.32-510.32-5+deb10u1
LowDLA-3239-1git@1:2.20.1-2+deb10u31:2.20.1-2+deb10u5
LowDSA-5147-1dpkg@1.19.71.19.8
LowDLA-3682-1ncurses@6.1+20181013-2+deb10u26.1+20181013-2+deb10u5
LowDSA-4919-1lz4@1.8.3-11.8.3-1+deb10u1
LowALPINE-CVE-2026-63075openssl@3.5.7-r03.5.8-r0
LowGHSA-cgx6-hpwq-fhv5nokogiri@1.10.101.13.5
LowALPINE-CVE-2026-60000openssh@10.3_p1-r010.3_p1-r1
LowGHSA-fq42-c5rg-92c2nokogiri@1.10.101.13.2
LowGHSA-v569-hp3g-36wrrack@2.2.32.2.23
LowDLA-3626-1krb5@1.17-3+deb10u11.17-3+deb10u6
LowGHSA-228g-948r-83gxloofah@2.8.02.19.1
LowALPINE-CVE-2026-82208curl@8.21.0-r08.22.0-r0
LowDSA-5174-1gnupg2@2.2.12-1+deb10u12.2.12-1+deb10u2
LowDSA-4933-1nettle@3.4.1-13.4.1-1+deb10u1
LowDSA-4930-1libwebp@0.6.1-20.6.1-2+deb10u1
LowALPINE-CVE-2026-75803openssl@3.5.7-r03.5.8-r0
LowGHSA-h2jq-g4cq-5ppqrack@2.2.32.2.23

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.4.2latest4 years agolatest06912274,629

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/geek-cookbook/gollum.svg)](https://charts.stackradar.io/charts/geek-cookbook/gollum)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.