StackRadar

mattermost Helm chart

phntom

Scored 15 Sept 2026

Mattermost Team Edition server.

Latest 3.24.0 2 years agoapp version 9.3.0 3Artifact Hub

mattermost 3.24.0 deploys 2 container images: appropriate/curl and phntom/mattermost-team-edition. Across them, 796 findings3 critical, 17 high 2 on CISA KEV. The highest contribution is UBUNTU-CVE-2025-27363 in freetype 2.11.1+dfsg-1ubuntu0.2, fixed in 2.11.1+dfsg-1ubuntu0.3.

Radar Score

8,767317117659

796 findings over 2 of 2 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
appropriate/curllatest0591551
phntom/mattermost-team-edition9.3.03121086588,216

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

659 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGO-2024-3096github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowUBUNTU-CVE-2026-19542glibc@2.35-0ubuntu3.12.35-0ubuntu3.15
LowUBUNTU-CVE-2026-36849tiff@4.3.0-6ubuntu0.7no fix listed
LowUBUNTU-CVE-2026-53613util-linux@2.37.2-4ubuntu32.37.2-4ubuntu3.6
LowUBUNTU-CVE-2026-53615util-linux@2.37.2-4ubuntu32.37.2-4ubuntu3.6
LowUBUNTU-CVE-2026-77117glibc@2.35-0ubuntu3.12.35-0ubuntu3.15
LowUBUNTU-CVE-2026-80489glibc@2.35-0ubuntu3.12.35-0ubuntu3.15
LowUBUNTU-CVE-2025-68160openssl@3.0.2-0ubuntu1.123.0.2-0ubuntu1.21
LowUBUNTU-CVE-2025-61145tiff@4.3.0-6ubuntu0.74.3.0-6ubuntu0.12
LowGHSA-9w97-9rqx-8v4jgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.1.7
LowGO-2024-3338github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowGHSA-x3r8-2hmh-89f5github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20251031095924-e7e23b94e006
LowUBUNTU-CVE-2025-32365poppler@22.02.0-2ubuntu0.322.02.0-2ubuntu0.7
LowGO-2025-3534github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowGHSA-vvpg-55p7-5h8wgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20240626164322-c758cecaf30c
LowGO-2026-4403stdlib@go1.20.71.23.9
LowUBUNTU-CVE-2026-59845libssh@0.9.6-2ubuntu0.22.04.10.9.6-2ubuntu0.22.04.8
LowGHSA-hm57-h27x-599cgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20240821220019-0d6b1070a26f
LowUBUNTU-CVE-2023-29383shadow@1:4.8.1-2ubuntu2.1no fix listed
LowUBUNTU-CVE-2025-32415libxml2@2.9.13+dfsg-1ubuntu0.32.9.13+dfsg-1ubuntu0.7
LowGHSA-j6gg-r5jc-47cmgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250815165020-c8d66301415d
LowGHSA-q8fg-cp3q-5jwmgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250102081831-64c566a8280b
LowGHSA-8cgx-9ccj-3gwrgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250414095146-04676582cdd2
LowGHSA-qqc8-rv37-79q5github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b0.0.0-20240209181221-674f549daf0e
LowGO-2026-5025golang.org/x/net@v0.17.00.55.0
LowGHSA-h3gq-j7p9-x3p4github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.1.7
LowGHSA-fmqf-pmcm-8cx9github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20251121122154-b57c297c6d7
LowGHSA-762g-9p7f-mrwwgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20240926115259-20ed58906adc
LowGO-2026-4970stdlib@go1.20.71.25.12
LowGO-2022-0635github.com/aws/aws-sdk-go@v1.44.293no fix listed
LowGO-2025-3552github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowGHSA-5mr9-crcg-8wh2github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20260130144323-5bb5261c72fa
LowUBUNTU-CVE-2025-15224curl@7.81.0-1ubuntu1.147.81.0-1ubuntu1.22
LowGHSA-p6gj-jc38-x2m7github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowUBUNTU-CVE-2023-6228tiff@4.3.0-6ubuntu0.74.3.0-6ubuntu0.8
LowGO-2024-2696github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowGO-2026-5027golang.org/x/net@v0.17.00.55.0
LowGO-2026-5029golang.org/x/net@v0.17.00.55.0
LowGO-2026-5030golang.org/x/net@v0.17.00.55.0
LowGO-2024-3093github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowUBUNTU-CVE-2026-42250bzip2@1.0.8-5build11.0.8-5ubuntu0.1
LowGHSA-7rgp-4j56-fm79github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250102081831-64c566a8280b
LowUBUNTU-CVE-2026-32777expat@2.4.7-1ubuntu0.2no fix listed
LowGHSA-wgvp-jj4w-88hfgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250513065225-4ae5d647fb88
LowGHSA-fx49-m253-27jjgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20260105134819-cc427af41b2a
LowUBUNTU-CVE-2025-9820gnutls28@3.7.3-4ubuntu1.23.7.3-4ubuntu1.8
LowUBUNTU-CVE-2026-39113sqlite3@3.37.2-2ubuntu0.1no fix listed
LowGO-2025-3555github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowUBUNTU-CVE-2026-0968libssh@0.9.6-2ubuntu0.22.04.10.9.6-2ubuntu0.22.04.6
LowGHSA-679f-wmrg-qf57github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20260113182106-a18b80ba4c32

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.24.0latest2 years ago9.3.03171176598,767

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/phntom/mattermost.svg)](https://charts.stackradar.io/charts/phntom/mattermost)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.