StackRadar

umami Helm chart

kubernetes-homelab-helm-chartsVerified publisher

Scored 14 Sept 2026

A Helm chart for Umami, a privacy-focused web analytics platform

Latest 0.1.0 30 days agoapp version 3.1.0 0Artifact Hub

umami 0.1.0 deploys 3 container images: library/busybox, ghcr.io/umami-software/umami and library/postgres. Across them, 239 findings0 critical, 2 high. The highest contribution is GHSA-c4j6-fc7j-m34r in next 16.2.4, fixed in 16.2.5.

Radar Score

2,5960235202

239 findings over 3 of 3 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
library/busybox1.3600000
ghcr.io/umami-software/umami3.1.002311462,103
library/postgres17-alpine00456493

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

196 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGO-2026-4341stdlib@go1.24.61.24.12
LowGHSA-4c39-4ccg-62r3next@16.2.416.2.11
LowALPINE-CVE-2026-9547curl@8.17.0-r18.22.0-r0
LowGHSA-955p-x3mx-jcvpnext@16.2.416.2.11
LowALPINE-CVE-2026-6276curl@8.17.0-r18.20.0-r0
LowGHSA-4gxm-v5v7-fqc4pnpm@10.33.010.34.2
LowGHSA-f886-m6hf-6m8vbrace-expansion@2.0.22.0.3
LowGHSA-88fw-hqm2-52qchono@4.11.44.12.25
LowALPINE-CVE-2026-9080curl@8.17.0-r18.22.0-r0
LowALPINE-CVE-2026-42767openssl@3.5.6-r03.5.7-r0
LowALPINE-CVE-2026-5545curl@8.17.0-r18.20.0-r0
LowALPINE-CVE-2026-3784curl@8.17.0-r18.19.0-r0
LowALPINE-CVE-2026-9545curl@8.17.0-r18.22.0-r0
LowALPINE-CVE-2025-14819curl@8.17.0-r18.18.0-r0
LowGHSA-38f7-945m-qr2geffect@3.18.43.20.0
LowGHSA-xf4j-xp2r-rqqxhono@4.11.44.12.12
LowALPINE-CVE-2026-76642util-linux@2.42.1-r02.42.3-r0
LowGHSA-3qhv-2rgh-x77rpnpm@10.33.010.34.2
LowALPINE-CVE-2026-63074openssl@3.5.6-r03.5.8-r0
LowGHSA-5qjj-4xww-7phcvalibot@1.2.01.4.2
LowALPINE-CVE-2025-14524curl@8.17.0-r18.18.0-r0
LowGHSA-w8wr-v893-vjvptar@7.5.127.5.18
LowALPINE-CVE-2026-34181openssl@3.5.6-r03.5.7-r0
LowGHSA-gqvv-2mrq-wpjvhono@4.11.44.13.5
LowGHSA-wwfh-h76j-fc44hono@4.11.44.12.25
LowGHSA-4633-3j49-mh5qnext@16.2.416.2.11
LowGHSA-2xp9-vwfh-vxw4next@16.2.416.3.3
LowGHSA-p4xf-rf54-rj3xpnpm@10.33.010.34.0
LowGHSA-gj8w-mvpf-x27xpnpm@10.33.010.34.2
LowGHSA-52v5-jr5w-gjxrsigstore@3.1.04.1.1
LowALPINE-CVE-2026-6429curl@8.17.0-r18.20.0-r0
LowGHSA-5wx6-mg75-v57rpnpm@10.33.010.34.2
LowGHSA-gvwx-54wh-qm9jtar@7.5.127.5.17
LowGHSA-w62v-xxxg-mg59hono@4.11.44.12.27
LowGHSA-8j4g-w8fx-2239hono@4.11.44.12.34
LowGHSA-68g3-v927-f742next@16.2.416.2.11
LowGHSA-hg3w-7f8c-63hppnpm@10.33.010.33.4
LowALPINE-CVE-2026-1965curl@8.17.0-r18.19.0-r0
LowGHSA-crvj-82cr-hjcxhono@4.11.44.13.5
LowGHSA-rgj7-g3m4-5g8csharp@0.34.50.35.4
LowALPINE-CVE-2026-7168curl@8.17.0-r18.20.0-r0
LowGHSA-v2v4-37r5-5v8gip-address@10.1.010.1.1
LowGHSA-6wqw-2p9w-4vw4hono@4.11.44.11.7
LowGHSA-wmmm-f939-6g9chono@4.11.44.12.12
LowALPINE-CVE-2026-3783curl@8.17.0-r18.19.0-r0
LowALPINE-CVE-2026-4873curl@8.17.0-r18.20.0-r0
LowGHSA-p6xx-57qc-3wxrhono@4.11.44.12.4
LowGHSA-w332-q679-j88phono@4.11.44.11.7
LowGHSA-26pp-8wgv-hjvmhono@4.11.44.12.12
LowGHSA-3v7f-55p6-f55ppicomatch@4.0.34.0.4

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.1.0latest30 days ago3.1.002352022,596

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubernetes-homelab-helm-charts/umami.svg)](https://charts.stackradar.io/charts/kubernetes-homelab-helm-charts/umami)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.