StackRadar

docmost Helm chart

helmforgeVerified publisher

Scored 14 Sept 2026

Docmost collaborative wiki and documentation software with PostgreSQL, Redis, local storage, and optional S3

Latest 1.2.11 2 days agoapp version 0.95.0 4Artifact Hub

docmost 1.2.11 deploys 4 container images: library/busybox, docmost/docmost, library/postgres and library/redis. Across them, 558 findings0 critical, 0 high. The highest contribution is DEBIAN-CVE-2019-1010022 in glibc 2.36-9+deb12u14, with no fix listed. Chart.yaml declares kubeVersion >=1.26.0-0; rendered for Kubernetes 1.26.0.

Radar Score

5,5640063495

558 findings over 4 of 4 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

4 images
ImageTagVulnerabilitiesRadar Score
library/busybox×21.3700000
docmost/docmost0.95.000322512,983
library/postgres18.6-trixie00191591,626
library/redis8.10.1001285955

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

360 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDEBIAN-CVE-2026-13608curl@7.88.1-10+deb12u14no fix listed
LowDEBIAN-CVE-2026-5773curl@7.88.1-10+deb12u147.88.1-10+deb12u15
LowDEBIAN-CVE-2026-63072openssl@3.0.20-1~deb12u2no fix listed
LowGHSA-gr94-w7qr-f4j3engine.io@6.6.26.6.7
LowDEBIAN-CVE-2026-85091zlib@1:1.2.13.dfsg-1no fix listed
LowGHSA-qffp-2rhf-9h96tar@7.4.37.5.10
LowDEBIAN-CVE-2026-80230curl@7.88.1-10+deb12u14no fix listed
LowGHSA-23hp-3jrh-7fpwtar@7.5.117.5.19
LowGHSA-93r5-fhx6-vmg9@xmldom/xmldom@0.8.130.8.15
LowGHSA-965w-775f-mr7g@xmldom/xmldom@0.8.130.8.15
LowGHSA-27p8-2357-5qqv@xmldom/xmldom@0.8.130.8.15
LowGHSA-4w3w-2rp5-g8jm@xmldom/xmldom@0.8.130.8.14
LowGHSA-c7q8-3ch8-vqpv@xmldom/xmldom@0.8.130.8.15
LowGHSA-w2rr-34g9-rvrj@xmldom/xmldom@0.8.130.8.14
LowDEBIAN-CVE-2024-2236libgcrypt20@1.10.1-3+deb12u1no fix listed
LowGHSA-8344-3jmq-59r6@xmldom/xmldom@0.8.130.8.15
LowGHSA-hmw2-7cc7-3qxxform-data@4.0.54.0.6
LowGHSA-qrv3-253h-g69cpnpm@10.4.010.34.4
LowDEBIAN-CVE-2026-54874openssl@3.0.20-1~deb12u2no fix listed
LowGHSA-7r86-cg39-jmmjminimatch@9.0.59.0.7
LowDEBIAN-CVE-2026-74860libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3no fix listed
LowGHSA-2m8v-j782-fhvrsocket.io-parser@4.2.64.2.7
LowDEBIAN-CVE-2025-69720ncurses@6.4-4no fix listed
LowGHSA-gcfj-64vw-6mp9axios@1.16.01.18.0
LowGHSA-8qq5-rm4j-mr97tar@7.4.37.5.3
LowDEBIAN-CVE-2026-86145pcre2@10.42-110.42-1+deb12u1
LowDEBIAN-CVE-2026-63075openssl@3.5.6-1~deb13u23.5.7-1~deb13u2
LowGHSA-w466-c33r-3gjppnpm@10.4.010.34.2
LowGHSA-v39h-62p7-jpjcfast-uri@3.0.63.1.2
LowGHSA-23c5-xmqv-rm74minimatch@9.0.59.0.7
LowGHSA-x4fp-j954-r2f4@xmldom/xmldom@0.8.130.8.15
LowGHSA-mh99-v99m-4gvgbrace-expansion@2.0.22.1.3
LowDEBIAN-CVE-2026-24882gnupg2@2.4.7-21+deb13u1+b4no fix listed
LowDEBIAN-CVE-2026-9538perl@5.36.0-7+deb12u3no fix listed
LowGHSA-4cwx-7wf7-3272undici@7.28.07.29.0
LowDEBIAN-CVE-2026-58050libssh2@1.10.0-3+b11.10.0-3+deb12u1
LowDEBIAN-CVE-2020-15719openldap@2.5.13+dfsg-5no fix listed
LowGHSA-v2hh-gcrm-f6hxfast-uri@3.0.63.1.4
LowDEBIAN-CVE-2026-66034libssh2@1.10.0-3+b11.10.0-3+deb12u1
LowGHSA-7vhp-vf5g-r2fwpnpm@10.4.010.26.0
LowGHSA-8x88-c5mf-7j5wtar@7.5.117.5.18
LowDEBIAN-CVE-2025-15661libssh2@1.10.0-3+b11.10.0-3+deb12u1
LowDEBIAN-CVE-2026-54411pam@1.5.2-6+deb12u2no fix listed
LowDEBIAN-CVE-2026-42497perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2026-41992gzip@1.12-1no fix listed
LowGHSA-vq4v-j7r6-jq4mpnpm@10.4.010.34.5
LowGHSA-c2c7-rcm5-vvqjpicomatch@4.0.34.0.4
LowDEBIAN-CVE-2026-12064curl@7.88.1-10+deb12u14no fix listed
LowGHSA-mwp4-54f8-5fhrip-address@10.1.010.3.1
LowDEBIAN-CVE-2026-8932curl@7.88.1-10+deb12u14no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.2.11latest2 days ago0.95.000634955,564

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/helmforge/docmost.svg)](https://charts.stackradar.io/charts/helmforge/docmost)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.