StackRadar

matomo Helm chart

t3n

Scored 14 Sept 2026

Latest 1.3.1 5 years agoapp version 4.3.1 1Artifact Hub

matomo 1.3.1 deploys 4 container images: library/busybox, library/mysql, t3nde/matomo and library/nginx. Across them, 189 findings2 critical, 14 high. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1k-r0, fixed in 1.1.1l-r0.

Radar Score

4,26421411162

189 findings over 4 of 4 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

4 images
ImageTagVulnerabilitiesRadar Score
library/busybox1.3200000
library/mysql8.0.22001733829
t3nde/matomo4.3.1-fpm-alpine11272242,646
library/nginx1.18.0-alpine12225789

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

170 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumDSA-4942-1systemd@241-7~deb10u5241-7~deb10u8
MediumALPINE-CVE-2021-3541libxml2@2.9.10-r42.9.12-r0
MediumALPINE-CVE-2022-43552curl@7.77.0-r17.79.1-r4
MediumALPINE-CVE-2021-38115gd@2.2.5-r32.2.5-r4
MediumALPINE-CVE-2022-29458ncurses@6.2_p20210612-r06.2_p20210612-r1
MediumALPINE-CVE-2023-23916curl@7.77.0-r17.79.1-r5
MediumALPINE-CVE-2021-35604mariadb@10.5.11-r010.5.13-r0
MediumDLA-3530-1openssl@1.1.1d-0+deb10u41.1.1n-0+deb10u6
MediumALPINE-CVE-2023-27537curl@7.77.0-r18.0.1-r0
MediumDLA-3152-1glibc@2.28-102.28-10+deb10u2
LowALPINE-CVE-2023-27535curl@7.77.0-r18.0.1-r0
LowALPINE-CVE-2022-24048mariadb@10.5.11-r010.5.15-r0
LowALPINE-CVE-2022-24052mariadb@10.5.11-r010.5.15-r0
LowALPINE-CVE-2022-27774curl@7.77.0-r17.79.1-r1
LowDSA-5122-1gzip@1.9-31.9-3+deb10u1
LowDSA-5123-1xz-utils@5.2.4-15.2.4-1+deb10u1
LowALPINE-CVE-2023-27536curl@7.77.0-r18.0.1-r0
LowALPINE-CVE-2021-22924curl@7.77.0-r17.78.0-r0
LowALPINE-CVE-2022-24051mariadb@10.5.11-r010.5.15-r0
LowALPINE-CVE-2022-24050mariadb@10.5.11-r010.5.15-r0
LowALPINE-CVE-2021-40528libgcrypt@1.8.5-r01.8.8-r1
LowALPINE-CVE-2021-22923curl@7.67.0-r37.79.0-r0
LowDSA-5087-1cyrus-sasl2@2.1.27+dfsg-1+deb10u12.1.27+dfsg-1+deb10u2
LowALPINE-CVE-2021-2372mariadb@10.5.11-r010.5.12-r0
LowALPINE-CVE-2022-48303tar@1.34-r01.34-r1
LowALPINE-CVE-2023-23915curl@7.77.0-r17.79.1-r5
LowALPINE-CVE-2023-0465openssl@1.1.1k-r01.1.1t-r2
LowALPINE-CVE-2023-27538curl@7.77.0-r18.0.1-r0
LowDSA-5147-1dpkg@1.19.71.19.8
LowDLA-3682-1ncurses@6.1+20181013-2+deb10u26.1+20181013-2+deb10u5
LowDSA-4919-1lz4@1.8.3-11.8.3-1+deb10u1
LowALPINE-CVE-2020-8284curl@7.67.0-r37.79.0-r0
LowDSA-5174-1gnupg2@2.2.12-1+deb10u12.2.12-1+deb10u2
LowDSA-4933-1nettle@3.4.1-13.4.1-1+deb10u1
LowDLA-3782-1util-linux@2.33.1-0.12.33.1-0.1+deb10u1
LowDLA-3586-1ncurses@6.1+20181013-2+deb10u26.1+20181013-2+deb10u4
LowDLA-3263-1libtasn1-6@4.13-34.13-3+deb10u1
LowALPINE-CVE-2021-22898curl@7.67.0-r37.67.0-r4
LowDLA-3070-1gnutls28@3.6.7-4+deb10u53.6.7-4+deb10u9
LowDLA-3153-1libksba@1.3.5-21.3.5-2+deb10u1
LowDLA-3740-1gnutls28@3.6.7-4+deb10u53.6.7-4+deb10u12
LowDLA-3248-1libksba@1.3.5-21.3.5-2+deb10u2
LowALPINE-CVE-2022-35252curl@7.77.0-r17.79.1-r3
LowALPINE-CVE-2021-42374busybox@1.31.1-r101.31.1-r11
LowALPINE-CVE-2021-46659mariadb@10.5.11-r010.5.15-r0
LowDLA-3321-1gnutls28@3.6.7-4+deb10u53.6.7-4+deb10u10
LowDLA-3167-1ncurses@6.1+20181013-2+deb10u26.1+20181013-2+deb10u3
LowDLA-3850-1glibc@2.28-102.28-10+deb10u4
LowDLA-3660-1gnutls28@3.6.7-4+deb10u53.6.7-4+deb10u11
LowDLA-3107-1sqlite3@3.27.2-3+deb10u13.27.2-3+deb10u2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.3.1latest5 years ago4.3.1214111624,264

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/t3n/matomo.svg)](https://charts.stackradar.io/charts/t3n/matomo)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.