StackRadar

matomo Helm chart

pockostVerified publisher

Scored 14 Sept 2026

This Helm Chart deploys a highly secured Matomo instance, optimized for demanding production environments.

Latest 1.3.0app version 5.13.0 1Artifact Hub

matomo 1.3.0 deploys 3 container images: pockost/matomo, library/mariadb and library/redis. Across them, 532 findings0 critical, 0 high. The highest contribution is DEBIAN-CVE-2018-6951 in patch 2.8-2, with no fix listed.

Radar Score

5,0470056475

532 findings over 3 of 3 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
pockost/matomo×35.13.000261972,217
library/mariadb12.3.300181931,875
library/redis×28.10.1001285955

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

353 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2026-53801rsync@3.2.7-1ubuntu1.5no fix listed
LowDEBIAN-CVE-2013-4392systemd@257.13-1~deb13u1no fix listed
LowUBUNTU-CVE-2025-29481libbpf@1:1.3.0-2build2no fix listed
LowDEBIAN-CVE-2026-78408util-linux@2.41.5-0+deb13u1no fix listed
LowUBUNTU-CVE-2026-53794rsync@3.2.7-1ubuntu1.5no fix listed
LowUBUNTU-CVE-2026-41989libgcrypt20@1.10.3-2ubuntu0.11.12.0-2ubuntu0.1~Fips1~rc11
LowUBUNTU-CVE-2026-13595util-linux@2.39.3-9ubuntu6.52.39.3-9ubuntu6.6
LowUBUNTU-CVE-2026-47052mariadb@1:12.3.3+maria~ubu2404no fix listed
LowGO-2026-4981stdlib@go1.24.61.25.10
LowDEBIAN-CVE-2023-31439systemd@257.13-1~deb13u1no fix listed
LowUBUNTU-CVE-2026-60183mariadb@1:12.3.3+maria~ubu2404no fix listed
LowUBUNTU-CVE-2026-60331mariadb@1:12.3.3+maria~ubu2404no fix listed
LowUBUNTU-CVE-2026-60332mariadb@1:12.3.3+maria~ubu2404no fix listed
LowGO-2026-4977stdlib@go1.24.61.25.10
LowDEBIAN-CVE-2026-76957expat@2.8.3-1~deb13u1no fix listed
LowDEBIAN-CVE-2023-31437systemd@257.13-1~deb13u1no fix listed
LowGO-2026-4986stdlib@go1.24.61.25.10
LowGO-2026-4918stdlib@go1.24.61.25.10
LowUBUNTU-CVE-2023-52968mariadb@1:12.3.3+maria~ubu2404no fix listed
LowGO-2026-4337stdlib@go1.24.61.24.13
LowDEBIAN-CVE-2023-31438systemd@257.13-1~deb13u1no fix listed
LowUBUNTU-CVE-2026-60145mariadb@1:12.3.3+maria~ubu2404no fix listed
LowDEBIAN-CVE-2025-3198binutils@2.44-3no fix listed
LowGO-2026-4601stdlib@go1.24.61.25.8
LowUBUNTU-CVE-2026-53798rsync@3.2.7-1ubuntu1.5no fix listed
LowUBUNTU-CVE-2026-60747mariadb@1:12.3.3+maria~ubu2404no fix listed
LowDEBIAN-CVE-2026-78410util-linux@2.41.5-0+deb13u1no fix listed
LowDEBIAN-CVE-2026-89161pcre2@10.46-1~deb13u110.46-1~deb13u2
LowGO-2026-5026stdlib@go1.24.61.25.13
LowUBUNTU-CVE-2026-44171mariadb@1:12.3.3+maria~ubu2404no fix listed
LowDEBIAN-CVE-2026-86142libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3no fix listed
LowUBUNTU-CVE-2026-42014gnutls28@3.8.3-1.1ubuntu3.63.8.3-1.1ubuntu3.6+Fips1.2
LowGO-2026-4342stdlib@go1.24.61.24.12
LowDEBIAN-CVE-2025-11839binutils@2.44-3no fix listed
LowDEBIAN-CVE-2025-11840binutils@2.44-3no fix listed
LowDEBIAN-CVE-2026-78409util-linux@2.41.5-0+deb13u1no fix listed
LowDEBIAN-CVE-2025-69648binutils@2.44-3no fix listed
LowDEBIAN-CVE-2025-69652binutils@2.44-3no fix listed
LowDEBIAN-CVE-2025-69651binutils@2.44-3no fix listed
LowGO-2026-4870stdlib@go1.24.61.25.9
LowDEBIAN-CVE-2025-11495binutils@2.44-3no fix listed
LowGO-2025-4009stdlib@go1.24.61.24.8
LowDEBIAN-CVE-2026-86138libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3no fix listed
LowGO-2026-4947stdlib@go1.24.61.25.9
LowDEBIAN-CVE-2026-86143libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3no fix listed
LowDEBIAN-CVE-2010-4651patch@2.8-2no fix listed
LowGO-2025-4006stdlib@go1.24.61.24.8
LowDEBIAN-CVE-2026-4647binutils@2.44-3no fix listed
LowUBUNTU-CVE-2026-47023mariadb@1:12.3.3+maria~ubu2404no fix listed
LowGO-2026-5037stdlib@go1.24.61.25.11

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.3.0latest5.13.000564755,047

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/pockost/matomo.svg)](https://charts.stackradar.io/charts/pockost/matomo)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 13 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.