StackRadar

mattermost Helm chart

phntom

Scored 14 Sept 2026

Mattermost Team Edition server.

Latest 3.24.0 2 years agoapp version 9.3.0 3Artifact Hub

mattermost 3.24.0 deploys 2 container images: appropriate/curl and phntom/mattermost-team-edition. Across them, 788 findings4 critical, 16 high 2 on CISA KEV. The highest contribution is UBUNTU-CVE-2025-27363 in freetype 2.11.1+dfsg-1ubuntu0.2, fixed in 2.11.1+dfsg-1ubuntu0.3.

Radar Score

8,722416117651

788 findings over 2 of 2 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
appropriate/curllatest0591551
phntom/mattermost-team-edition9.3.04111086508,171

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

788 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2025-5278coreutils@8.32-4.1ubuntu18.32-4.1ubuntu1.4
LowGO-2026-5856stdlib@go1.20.71.25.12
LowUBUNTU-CVE-2026-22795openssl@3.0.2-0ubuntu1.123.0.2-0ubuntu1.21
LowGO-2025-4007stdlib@go1.20.71.24.9
LowGO-2026-6355golang.org/x/crypto@v0.14.00.56.0
LowGHSA-h356-3mfw-x368github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250411064244-844447fbd57c
LowGO-2025-3550github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowGO-2026-4980stdlib@go1.20.71.25.10
LowUBUNTU-CVE-2026-42770openssl@3.0.2-0ubuntu1.123.0.2-0ubuntu1.25
LowGO-2026-5039stdlib@go1.20.71.25.11
LowUBUNTU-CVE-2025-3360glib2.0@2.72.4-0ubuntu2.22.72.4-0ubuntu2.7
LowGO-2024-2635github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowGHSA-6mvp-gh77-7vwhgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20240813135334-8f3a13122f55
LowUBUNTU-CVE-2026-41254lcms2@2.12~rc1-2build22.12~rc1-2ubuntu0.1
LowGO-2024-3092github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowUBUNTU-CVE-2025-8114libssh@0.9.6-2ubuntu0.22.04.10.9.6-2ubuntu0.22.04.5
LowGHSA-q8p2-2hwc-jw64github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250110161910-96195f1bd746
LowUBUNTU-CVE-2026-1484glib2.0@2.72.4-0ubuntu2.22.72.4-0ubuntu2.9
LowGO-2025-4013stdlib@go1.20.71.24.8
LowGO-2025-3849stdlib@go1.20.71.23.12
LowGO-2026-4946stdlib@go1.20.71.25.9
LowGHSA-2v3w-6g35-5f9vgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20260129181235-1346cf529aef
LowGHSA-7cr3-38jm-6p45github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250822090405-e8c7e7d0252b
LowGHSA-mj2p-v2c2-vh4vgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250314142426-c049748b8863
LowGO-2022-0646github.com/aws/aws-sdk-go@v1.44.293no fix listed
LowGHSA-g376-m3h3-mj4rgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20240926115259-20ed58906adc
LowGO-2024-3094github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowUBUNTU-CVE-2026-54370acl@2.3.1-1no fix listed
LowGO-2024-3091github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowGO-2026-5066golang.org/x/image@v0.8.00.43.0
LowUBUNTU-CVE-2026-56412expat@2.4.7-1ubuntu0.2no fix listed
LowGO-2024-3028github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowGHSA-4578-6gjh-f2jmgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250520060012-d0380305ef7a
LowGO-2026-4961golang.org/x/image@v0.8.00.42.0
LowGO-2024-3024github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowUBUNTU-CVE-2026-56131expat@2.4.7-1ubuntu0.2no fix listed
LowGHSA-h4rr-f37j-4hh7github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20250314142426-c049748b8863
LowUBUNTU-CVE-2026-50219expat@2.4.7-1ubuntu0.2no fix listed
LowGHSA-xv2p-wchj-qjhpgithub.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4b8.0.0-20260123215601-86797c508c44
LowGO-2024-2706github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowGO-2025-3551github.com/mattermost/mattermost/server/v8@v0.0.0-20231206131006-d6edda074a4bno fix listed
LowUBUNTU-CVE-2025-15649perl@5.34.0-3ubuntu1.3no fix listed
LowGO-2026-4603stdlib@go1.20.71.25.8
LowUBUNTU-CVE-2026-0988glib2.0@2.72.4-0ubuntu2.22.72.4-0ubuntu2.8
LowGO-2026-6303golang.org/x/crypto@v0.14.00.55.0
LowGO-2026-6354golang.org/x/crypto@v0.14.00.56.0
LowUBUNTU-CVE-2026-29111systemd@249.11-0ubuntu3.7249.11-0ubuntu3.19
LowUBUNTU-CVE-2025-7039glib2.0@2.72.4-0ubuntu2.22.72.4-0ubuntu2.7
LowGO-2026-4982stdlib@go1.20.71.25.10
LowGO-2026-6091stdlib@go1.20.71.25.13

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.24.0latest2 years ago9.3.04161176518,722

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/phntom/mattermost.svg)](https://charts.stackradar.io/charts/phntom/mattermost)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.