StackRadar

mastodon Helm chart

rivals-spaceVerified publisher

Scored 14 Sept 2026

Rivals.space Mastodon helm chart

Latest 3.1.2 3 years agoapp version 1.6.1 0Artifact Hub

mastodon 3.1.2 deploys 3 container images: ghcr.io/rivals-space/rivals-nginx, ghcr.io/rivals-space/rivals-mastodon and bitnami/redis. Across the 2 measured, 456 findings1 critical, 14 high 4 on CISA KEV. The highest contribution is GHSA-754f-8gm6-c4r2 in ruby-saml 1.13.0, fixed in 1.18.0.

Radar Score

6,02611490351

456 findings over 2 of 3 images measured

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/rivals-space/rivals-nginx1.6.1061918929
ghcr.io/rivals-space/rivals-mastodon×81.6.118713335,097
bitnami/redis7.0.5-debian-11-r15unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

90 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumGHSA-h47h-mwp9-c6q6actionmailer@6.1.7.26.1.7.9
MediumGHSA-q339-8rmv-2mhverb@2.2.04.0.3.1
MediumGHSA-2rxp-v6pw-ch6mrexml@3.2.53.3.9
MediumGHSA-3h5v-q93c-6h6qws@7.4.67.5.10
MediumGHSA-r55c-59qm-vjw6rexml@3.2.53.3.3
MediumALPINE-CVE-2024-0727openssl@3.0.7-r23.0.12-r4
MediumGHSA-g857-hhfv-j68wzlib@2.0.03.0.1
MediumGHSA-hwj9-h5mp-3pm3postcss@7.0.327.0.36
MediumGHSA-jr5f-v2jv-69x6axios@1.3.21.8.2
MediumGHSA-95m3-7q98-8xr5sha.js@2.4.112.4.12
MediumGHSA-8hc4-vh64-cxmjaxios@1.3.21.7.4
MediumGHSA-5866-49gr-22v4rexml@3.2.53.3.3
MediumGHSA-gjh7-p2fx-99vxrack@2.2.6.22.2.14
MediumGHSA-7wqh-767x-r66vrack@2.2.6.22.2.13
MediumGHSA-4hjh-wcwx-xvwjaxios@1.3.21.12.0
MediumALPINE-CVE-2023-6237openssl@3.0.7-r23.0.12-r3
MediumALPINE-CVE-2024-9143openssl@3.0.7-r23.0.15-r1
MediumGHSA-9xrj-h377-fr87activestorage@6.1.7.27.2.3.1
MediumALPINE-CVE-2023-3817openssl@3.0.7-r23.0.10-r0
MediumGHSA-f23m-r3pf-42rhlodash@4.17.214.18.0
MediumGHSA-xxjr-mmjv-4gpglodash@4.17.214.17.23
MediumGHSA-xvcm-6775-5m9rimmutable@4.2.44.3.9
MediumGHSA-73f9-jhhh-hr5mactivestorage@6.1.7.27.2.3.1
MediumGHSA-67hx-6x53-jw92@babel/traverse@7.20.127.23.2
MediumALPINE-CVE-2025-9232openssl@3.0.7-r23.0.19-r0
MediumGHSA-2j26-frm8-cmj9activesupport@6.1.7.27.2.3.1
MediumGHSA-r46p-8f7g-vvvgactivestorage@6.1.7.27.2.3.1
MediumGHSA-37ch-88jc-xwx2path-to-regexp@0.1.70.1.13
MediumGHSA-9wv6-86v2-598jpath-to-regexp@1.7.01.9.0
MediumGHSA-p543-xpfm-54cprack@2.2.6.22.2.19
MediumGHSA-wpv5-97wm-hp9crack@2.2.6.22.2.19
MediumGHSA-cpq7-6gpm-g9rccipher-base@1.0.41.0.5
MediumGHSA-566m-qj78-rww5postcss@7.0.327.0.36
MediumALPINE-CVE-2025-69421openssl@3.0.7-r23.0.19-r0
MediumGHSA-3xgq-45jj-v275cross-spawn@6.0.56.0.6
MediumGHSA-p92q-9vqr-4j8vaxios@1.3.21.16.0
MediumGHSA-qwcr-r2fm-qrc7body-parser@1.20.11.20.3
MediumGHSA-96hv-2xvq-fx4pws@7.4.67.5.11
MediumGHSA-3ppc-4f35-3m26minimatch@5.0.15.1.7
MediumGHSA-pf86-5x62-jrwfaxios@1.3.21.15.1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.1.2latest3 years ago1.6.1114903516,026

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/rivals-space/mastodon.svg)](https://charts.stackradar.io/charts/rivals-space/mastodon)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.