StackRadar

mastodon Helm chart

rivals-spaceVerified publisher

Scored 14 Sept 2026

Rivals.space Mastodon helm chart

Latest 3.1.2 3 years agoapp version 1.6.1 0Artifact Hub

mastodon 3.1.2 deploys 3 container images: ghcr.io/rivals-space/rivals-nginx, ghcr.io/rivals-space/rivals-mastodon and bitnami/redis. Across the 2 measured, 456 findings1 critical, 14 high 4 on CISA KEV. The highest contribution is GHSA-754f-8gm6-c4r2 in ruby-saml 1.13.0, fixed in 1.18.0.

Radar Score

6,02611490351

456 findings over 2 of 3 images measured

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/rivals-space/rivals-nginx1.6.1061918929
ghcr.io/rivals-space/rivals-mastodon×81.6.118713335,097
bitnami/redis7.0.5-debian-11-r15unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

90 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumDLA-3859-1systemd@247.3-7+deb11u1247.3-7+deb11u6
MediumDSA-5591-1libssh@0.9.5-1+deb11u10.9.8-0+deb11u1
MediumDLA-4052-1postgresql-13@13.9-0+deb11u113.19-0+deb11u1
MediumDSA-5347-1imagemagick@8:6.9.11.60+dfsg-1.38:6.9.11.60+dfsg-1.3+deb11u1
MediumDSA-5673-1glibc@2.31-13+deb11u52.31-13+deb11u9
MediumGHSA-22f2-v57c-j9cxrack@2.2.6.22.2.8.1
MediumDSA-5417-1openssl@1.1.1n-0+deb11u41.1.1n-0+deb11u5
MediumALPINE-CVE-2024-5535openssl@3.0.7-r23.0.14-r0
MediumGHSA-r4mg-4433-c7g3activestorage@6.1.7.27.1.5.2
MediumDLA-3942-1openssl@1.1.1n-0+deb11u41.1.1n-0+deb11u6
MediumDLA-3942-2openssl@1.1.1n-0+deb11u41.1.1w-0+deb11u2
MediumALPINE-CVE-2022-4304openssl@3.0.7-r23.0.8-r0
MediumGHSA-76p3-8jx3-jpfqloader-utils@2.0.02.0.3
MediumGHSA-v5h6-c2hv-hv3rstringio@3.0.13.0.1.1
MediumGHSA-vx3p-948g-6vhqssri@8.0.08.0.1
MediumALPINE-CVE-2023-0215openssl@3.0.7-r23.0.8-r0
MediumGHSA-vc47-6rqg-c7f5cgi@0.2.10.2.2
MediumALPINE-CVE-2023-0464openssl@3.0.7-r23.0.8-r1
MediumGHSA-93q8-gq69-wqmwansi-regex@4.1.04.1.1
MediumGHSA-fjxv-7rqg-78g4form-data@4.0.04.0.4
MediumALPINE-CVE-2023-5363openssl@3.0.7-r23.0.12-r0
MediumGHSA-hxcc-f52p-wc94serialize-javascript@2.1.23.1.0
MediumGHSA-4wf5-vphf-c2xcterser@5.13.15.14.2
MediumALPINE-CVE-2024-4741openssl@3.0.7-r23.0.14-r0
MediumGHSA-mw96-cpmx-2vgcrollup@2.72.12.80.0
MediumGHSA-c2qf-rxjj-qqgwsemver@5.7.15.7.2
MediumGHSA-43fc-jf86-j433axios@1.3.21.13.5
MediumGHSA-hv5j-3h9f-99c2uri@0.10.10.10.2
MediumGHSA-ww4x-rwq6-qpgfomniauth@1.9.22.0.0
MediumGHSA-fg7x-g82r-94qctime@0.1.00.1.1
MediumALPINE-CVE-2023-3446openssl@3.0.7-r23.0.9-r3
MediumGHSA-hhq3-ff78-jv3gloader-utils@2.0.02.0.4
MediumGHSA-wf6x-7x77-mvgwimmutable@4.2.44.3.8
MediumGHSA-3rfm-jhwj-7488loader-utils@2.0.02.0.4
MediumGHSA-rp65-9cf3-cjxrnth-check@1.0.22.0.1
MediumGHSA-68xg-gqqm-vgj8puma@5.6.55.6.7
MediumALPINE-CVE-2023-0216openssl@3.0.7-r23.0.8-r0
MediumALPINE-CVE-2023-0217openssl@3.0.7-r23.0.8-r0
MediumALPINE-CVE-2023-0401openssl@3.0.7-r23.0.8-r0
MediumGHSA-3h57-hmj3-gj3prack@2.2.6.22.2.6.3
MediumGHSA-x76w-6vjr-8xgjactionpack@6.1.7.26.1.7.9
MediumGHSA-72xf-g2v4-qvf3tough-cookie@4.1.24.1.3
MediumGHSA-vfg9-r3fq-jvx4actionpack@6.1.7.26.1.7.9
MediumGHSA-35jp-ww65-95whaxios@1.3.21.16.0
MediumALPINE-CVE-2023-5678openssl@3.0.7-r23.0.12-r1
MediumALPINE-CVE-2025-9230openssl@3.0.7-r23.0.19-r0
MediumGHSA-wwhv-wxv9-rpgwactiontext@6.1.7.26.1.7.9
MediumALPINE-CVE-2023-6129openssl@3.0.7-r23.0.12-r2
MediumGHSA-92rq-c8cf-prrqruby-saml@1.13.01.18.0
MediumGHSA-grv7-fg5c-xmjgbraces@3.0.23.0.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.1.2latest3 years ago1.6.1114903516,026

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/rivals-space/mastodon.svg)](https://charts.stackradar.io/charts/rivals-space/mastodon)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.