StackRadar

mealie 5.1.2 Helm chart

geek-cookbookVerified publisher

Scored 14 Sept 2026

Mealie is a self hosted recipe manager and meal planner with a RestAPI backend and a reactive frontend application built in Vue for a pleasant user experience for the whole family.

Version 5.1.2 4 years agodeploys tag frontend-v1.0.0beta-2 2Artifact Hub

mealie 5.1.2 deploys 2 container images: hkotel/mealie. Across them, 573 findings2 critical, 16 high 6 on CISA KEV. The highest contribution is GHSA-j7hp-h8jx-5ppr in pillow 8.4.0, fixed in 10.0.1. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.

Radar Score

7,579216122432

573 findings over 2 of 2 images measured

KEV ×6 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
hkotel/mealiefrontend-v1.0.0beta-2012722994,842
hkotel/mealieapi-v1.0.0beta-224501332,737

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

573 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-qrpm-p2h7-hrv2nanoid@3.1.303.1.31
LowGHSA-vjh7-7g9h-fjfhelliptic@6.5.46.6.1
LowGHSA-mf9w-mj56-hr94python-dotenv@0.15.01.2.2
LowGO-2024-3106stdlib@go1.17.101.22.7
LowGHSA-v6wh-96g9-6wx3launch-editor@2.3.02.14.1
LowGO-2023-1570stdlib@go1.17.101.19.6
LowDLA-4061-1libtasn1-6@4.16.0-24.16.0-2+deb11u2
LowGHSA-9f5j-8jwj-x28gecdsa@0.17.00.19.2
LowGHSA-378v-28hj-76wfbn.js@4.12.04.12.3
LowGO-2022-0531stdlib@go1.17.101.17.11
LowGO-2024-2600stdlib@go1.17.101.21.8
LowGHSA-fv7c-fp4j-7gwp@babel/plugin-transform-modules-systemjs@7.16.77.29.4
LowGHSA-977x-g7h5-7qgwelliptic@6.5.46.5.7
LowGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc@v1.39.01.82.1
LowGHSA-h8r8-wccr-v5f2dompurify@2.3.83.3.2
LowGHSA-28wg-ghj8-5hjvnanoid@3.1.303.3.16
LowGHSA-m6fv-jmcg-4jfgsend@0.17.20.19.0
LowGHSA-h7mw-gpvr-xq4mdompurify@2.3.83.4.0
LowGHSA-w9j2-pvgh-6h63axios@0.21.30.31.1
LowGO-2024-2609stdlib@go1.17.101.21.8
LowGO-2024-3107stdlib@go1.17.101.22.7
LowGO-2023-1751stdlib@go1.17.101.19.9
LowGO-2023-1753stdlib@go1.17.101.19.9
LowDLA-4145-1expat@2.2.10-2+deb11u32.2.10-2+deb11u7
LowGHSA-pq67-6m6q-mj2vurllib3@1.26.92.5.0
LowGHSA-2v37-7h3g-55p8nanoid@3.1.303.3.18
LowGHSA-58qx-3vcg-4xpxws@8.6.08.20.1
LowGHSA-4vpr-x523-8j87svgo@1.3.22.8.4
LowGHSA-9m57-25v3-79x9golang.org/x/crypto@v0.0.0-20210915214749-c084706c22720.52.0
LowGHSA-fc9h-whq2-v747elliptic@6.5.46.6.0
LowGHSA-3v7f-55p6-f55ppicomatch@2.3.12.3.2
LowGHSA-65pc-fj4g-8rjxidna@3.33.15
LowGHSA-mh29-5h37-fv8mjs-yaml@3.14.13.14.2
LowGO-2023-2041stdlib@go1.17.101.20.8
LowGHSA-9wx4-h78v-vm56requests@2.27.12.32.0
LowGHSA-7q8q-rj6j-mhjqaxios@0.21.30.33.0
LowGO-2023-2043stdlib@go1.17.101.20.8
LowGO-2022-0515stdlib@go1.17.101.17.12
LowGO-2023-2186stdlib@go1.17.101.20.11
LowGHSA-h67p-54hq-rp68js-yaml@3.14.13.15.0
LowGHSA-6v5v-wf23-fmfqmarkdown-it@12.2.014.2.0
LowDLA-4490-1openssl@1.1.1n-0+deb11u21.1.1w-0+deb11u5
LowGO-2024-3333golang.org/x/net@v0.0.0-20210913180222-943fd674d43e0.33.0
LowGHSA-vhxf-7vqr-mrjgdompurify@2.3.83.2.4
LowGHSA-3jxr-9vmj-r5cpbrace-expansion@1.1.111.1.16
LowGHSA-mwcw-c2x4-8c55nanoid@3.1.303.3.8
LowGHSA-76mc-f452-cxcmdompurify@2.3.83.4.7
LowGO-2024-3105stdlib@go1.17.101.22.7
LowGO-2022-1095stdlib@go1.17.101.18.8
LowGHSA-5c6j-r48x-rmvqserialize-javascript@5.0.17.0.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
5.1.2latest4 years agofrontend-v1.0.0beta-22161224327,579

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/geek-cookbook/mealie.svg)](https://charts.stackradar.io/charts/geek-cookbook/mealie)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.