StackRadar

mastodon Helm chart

rivals-spaceVerified publisher

Scored 14 Sept 2026

Rivals.space Mastodon helm chart

Latest 3.1.2 3 years agoapp version 1.6.1 0Artifact Hub

mastodon 3.1.2 deploys 3 container images: ghcr.io/rivals-space/rivals-nginx, ghcr.io/rivals-space/rivals-mastodon and bitnami/redis. Across the 2 measured, 456 findings1 critical, 14 high 4 on CISA KEV. The highest contribution is GHSA-754f-8gm6-c4r2 in ruby-saml 1.13.0, fixed in 1.18.0.

Radar Score

6,02611490351

456 findings over 2 of 3 images measured

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/rivals-space/rivals-nginx1.6.1061918929
ghcr.io/rivals-space/rivals-mastodon×81.6.118713335,097
bitnami/redis7.0.5-debian-11-r15unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

456 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDLA-4073-1ffmpeg@7:4.3.5-0+deb11u17:4.3.8-0+deb11u3
LowDLA-4396-1libpng1.6@1.6.37-31.6.37-3+deb11u1
LowDLA-4491-1glib2.0@2.66.8-12.66.8-1+deb11u8
LowGHSA-46q3-7gv7-qmggnet-imap@0.1.10.5.15
LowGHSA-wv3x-4vxv-whppconcurrent-ruby@1.2.01.3.7
LowGHSA-w7fw-mjwx-w883qs@6.11.06.14.2
LowALPINE-CVE-2026-22795openssl@3.0.7-r23.0.19-r0
LowDLA-4287-1libsndfile@1.0.31-21.0.31-2+deb11u1
LowGHSA-6rw7-vpxm-498pqs@6.11.06.14.1
LowDLA-4143-1glibc@2.31-13+deb11u52.31-13+deb11u12
LowDLA-3967-1mpg123@1.26.4-11.26.4-1+deb11u1
LowDLA-4195-1krb5@1.18.3-6+deb11u31.18.3-6+deb11u7
LowDLA-4420-1postgresql-13@13.9-0+deb11u113.23-0+deb11u1
LowGHSA-4g8v-vg43-wpgfactionpack@6.1.7.26.1.7.4
LowGHSA-v422-hmwv-36x6body-parser@1.20.11.20.6
LowGHSA-9wjq-cp2p-hrgfloofah@2.19.12.25.2
LowGHSA-v6h2-p8h4-qcjwbrace-expansion@2.0.12.0.2
LowGHSA-vpfw-47h7-xj4grack@2.2.6.22.2.14
LowDLA-4424-1openjpeg2@2.4.0-32.4.0-3+deb11u2
LowGHSA-22h5-pq3x-2gf2uri@0.10.10.11.3
LowALPINE-CVE-2025-68160openssl@3.0.7-r23.0.19-r0
LowGHSA-q2ww-5357-x388rack@2.2.6.22.2.23
LowGHSA-54rr-7fvw-6x8frack@2.2.6.22.2.8.1
LowDLA-4096-1librabbitmq@0.10.0-10.10.0-1+deb11u1
LowGHSA-xj5v-6v4g-jfw6rack@2.2.6.22.2.8.1
LowGHSA-vfm5-rmrh-j26vactionpack@6.1.7.27.0.8.7
LowDLA-4225-1gdk-pixbuf@2.42.2+dfsg-1+deb11u12.42.2+dfsg-1+deb11u3
LowDLA-4435-1libsodium@1.0.18-11.0.18-1+deb11u1
LowDLA-4469-1alsa-lib@1.2.4-1.11.2.4-1.1+deb11u1
LowGHSA-xhjh-pmcv-23jwaxios@1.3.21.15.1
LowDLA-4319-1libxml2@2.9.10+dfsg-6.7+deb11u32.9.10+dfsg-6.7+deb11u9
LowDLA-4437-1gnupg2@2.2.27-2+deb11u22.2.27-2+deb11u3
LowGHSA-v55j-83pf-r9cqactionview@6.1.7.27.2.3.1
LowGHSA-c6qg-cjj8-47qprack@2.2.6.22.2.6.4
LowALPINE-CVE-2025-69418openssl@3.0.7-r23.0.19-r0
LowDLA-3954-2postgresql-13@13.9-0+deb11u113.18-0+deb11u1
LowDLA-3972-1tzdata@2021a-1+deb11u82024b-0+deb11u1
LowDLA-4016-1ucf@3.00433.0043+deb11u2
LowDLA-4085-1tzdata@2021a-1+deb11u82025a-0+deb11u1
LowDLA-4105-1tzdata@2021a-1+deb11u82025b-0+deb11u1
LowDLA-4403-1tzdata@2021a-1+deb11u82025b-0+deb11u2
LowDLA-4485-1ca-certificates@2021011920230311+deb12u1~deb11u1
LowDSA-5682-2glib2.0@2.66.8-12.66.8-1+deb11u3
LowGHSA-pxg6-pf52-xh8xcookie@0.5.00.7.0
LowGHSA-q2mw-fvj9-vvcwnet-imap@0.1.10.4.24
LowGHSA-4gmj-3p3h-gm8hes5-ext@0.10.530.10.63
LowGHSA-4x5r-pxfx-6jf8@babel/core@7.20.127.29.6
LowGHSA-vpq2-c234-7xj6@tootallnate/once@2.0.02.0.1
LowGHSA-8678-w3jw-xfc2nokogiri@1.14.11.19.4
LowGHSA-vvfq-8hwr-qm4mnokogiri@1.14.11.18.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.1.2latest3 years ago1.6.1114903516,026

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/rivals-space/mastodon.svg)](https://charts.stackradar.io/charts/rivals-space/mastodon)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.