StackRadar

CVE-2026-12087

Critical

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,352
of 17,792 indexed, latest versions
Container images
2,313
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,352 of 17,792 indexed charts deploy, on 2,313 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+41 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,313
OSV records
DEBIAN-CVE-2026-12087UBUNTU-CVE-2026-12087ECHO-31e4-d78e-2b62
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,352 by stars
ChartLatestAffected imagesRadar Score
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-12087.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
yandex/clickhouse-server:21.3.204eccfffb01d7
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

9,256
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-12087.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8

Open the chart page →

7,929

Container images carrying it

2,313 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
arthurjguerra18/revwallet:v0.7.12f540af20b307
perl@5.36.0-7+deb12u1
no fix listed
1
artifacthub/tracker:v1.23.05368d21a6e5c
perl@5.40.1-6
5.40.1-6+deb13u1
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
perl@5.36.0-7+deb12u1
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
assistiot/identity-manager_db:latest0d3e6d35f168
perl@5.36.0-7
no fix listed
1
assistiot/location_processing:lateste9bae124095f
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
1
assistiot/open_api_backend:1.1.230812ba93555
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
perl@5.36.0-7+deb12u1
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
perl@5.36.0-7+deb12u1
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
perl@5.36.0-7
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
athou/commafeed:6.2.0-postgresql5e388351df1a
perl@5.40.1-6
5.40.1-6+deb13u1
1
atlassian/confluence-server:7.10.03b9222ab32ef
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
1
atlassian/jira-software:8.14.037bc46cbec1a
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
atlassian/jira-software:9.7.264a75aa4ec4e
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
perl@5.36.0-7+deb12u1
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
perl@5.36.0-7
no fix listed
1
avzini/web-app:latestf40b30210ed0
perl@5.36.0-7
no fix listed
1
baserow/backend:2.3.37c00549b3a6f
perl@5.40.1-6
5.40.1-6+deb13u1
1
baserow/backend:1.31.1e0b3c8130b91
perl@5.36.0-7+deb12u1
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
perl@5.36.0-7+deb12u1
no fix listed
1
baserow/web-frontend:2.3.3566d24c7d9f5
perl@5.40.1-6
5.40.1-6+deb13u1
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
perl@5.40.1-6
5.40.1-6+deb13u1
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
perl@5.40.1-6
5.40.1-6+deb13u1
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
perl@5.36.0-7+deb12u2
no fix listed
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
bicarus/mx-notifier:1.1.8bed688d16762
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/clickhouse:24.6.2-debian-12-r3dcc172c6c55f
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/git:latest4b08d0c5af8d
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/kubectl:1.301249fc292e84
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.3164614ef8290f
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/kube-state-metrics:204a3044b384b
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.