StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,382
of 17,792 indexed, latest versions
Container images
2,349
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,382 of 17,792 indexed charts deploy, on 2,349 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,311
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more38
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,382 by stars
ChartLatestAffected imagesRadar Score
jobopen-charts2.0.01 of 1See more

job open-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

738
bbsimopencord4.8.111 of 1See more

bbsim opencord 4.8.11

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
voltha/bbsim:1.16.7d90403d58016
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3

Open the chart page →

3,908
bbsim-sadis-serveropencord0.3.51 of 1See more

bbsim-sadis-server opencord 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
voltha/bbsim-sadis-server:0.4.0762b272d439e
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3

Open the chart page →

3,722
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3

Open the chart page →

63,280
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3
omecproject/onos-progran:1.0.05715e5648aa0
perl@5.22.1-9ubuntu0.2
5.22.1-9ubuntu0.9+esm3
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3

Open the chart page →

88,653
comac-cuopencord0.1.11 of 4See more

comac-cu opencord 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
perl@5.26.1-6
5.26.1-6ubuntu0.7+esm3

Open the chart page →

8,056
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3

Open the chart page →

26,246
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

15,718
mcord-cdn-remoteopencord0.1.62 of 2See more

mcord-cdn-remote opencord 0.1.6

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3
woojoong/wowza:latestec230db19652
perl@5.26.1-6ubuntu0.2
5.26.1-6ubuntu0.7+esm3

Open the chart page →

42,655
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3

Open the chart page →

29,156
mcord-control-planeopencord0.2.22 of 5See more

mcord-control-plane opencord 0.2.2

2 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
perl@5.22.1-9ubuntu0.5
5.22.1-9ubuntu0.9+esm3
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
perl@5.26.1-6
5.26.1-6ubuntu0.7+esm3

Open the chart page →

15,666
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

14,556
omec-control-planeopencord0.1.315 of 8See more

omec-control-plane opencord 0.1.31

5 of the 8 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
omecproject/c3po-hss:master-latest638671ef4842
perl@5.22.1-9ubuntu0.9
5.22.1-9ubuntu0.9+esm3
omecproject/c3po-hssdb:master-latest28a90cc26716
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
omecproject/mme-exporter:paging-latestbcc5f19fd676
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
omecproject/ngic-cp:central-cp-multi-upfs-latest24a389a0a4fe
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
omecproject/openmme:master-latest64776cb9edb3
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3

Open the chart page →

40,825
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

12,942
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
perl@5.22.1-9ubuntu0.2
5.22.1-9ubuntu0.9+esm3

Open the chart page →

38,902
ovspluginopencord1.0.21 of 1See more

ovsplugin opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
gopinatht/ovs-plugin-installer:latest632cb2e9c399
perl@5.22.1-9ubuntu0.3
5.22.1-9ubuntu0.9+esm3

Open the chart page →

4,172
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3

Open the chart page →

12,626
sebaopencord1.0.06 of 17See more

seba opencord 1.0.0

6 of the 17 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
perl@5.22.1-9ubuntu0.2
5.22.1-9ubuntu0.9+esm3
voltha/voltha-cli:1.6.0c4e41e92f046
perl@5.22.1-9ubuntu0.5
5.22.1-9ubuntu0.9+esm3
voltha/voltha-envoy:1.6.059ab2a00f712
perl@5.18.2-2ubuntu1.1
5.18.2-2ubuntu1.7+esm8
voltha/voltha-netconf:1.6.037f80524c207
perl@5.22.1-9ubuntu0.5
5.22.1-9ubuntu0.9+esm3
voltha/voltha-ofagent:1.6.09ee8c1f4428c
perl@5.22.1-9ubuntu0.5
5.22.1-9ubuntu0.9+esm3
voltha/voltha-voltha:1.6.0ff596b62de59
perl@5.22.1-9ubuntu0.5
5.22.1-9ubuntu0.9+esm3

Open the chart page →

93,946
voltha-infraopencord2.14.04 of 10See more

voltha-infra opencord 2.14.0

4 of the 10 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
library/ubuntu:16.041f1a2d56de1d
perl@5.22.1-9ubuntu0.9
5.22.1-9ubuntu0.9+esm3
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3
voltha/voltha-onos:5.1.8e038acb950d3
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

41,101
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,051
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8

Open the chart page →

1,737
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

5,068
openlit-controlleropenlit0.10.01 of 1See more

openlit-controller openlit 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,377
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8

Open the chart page →

3,465
llm-stackopenproject-helm-chartsVerified publisher1.1.02 of 2See more

llm-stack openproject-helm-charts 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
apache/apisix:3.16.0-ubuntu5e47692cac00
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
library/python:3.12-slim78387bc3881b
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,992
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-Compress-Raw-Bzip2@2.081-1.el8
perl-Compress-Raw-Zlib@2.081-1.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Digest-SHA@1:6.02-1.el8
perl-Encode@4:2.97-3.el8
perl-Encode-Locale@1.05-10.module+el8.3.0+6498+9eecfe51
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-2.el8
perl-IO-Compress@2.081-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.28-423.el8_10.1
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:2.096-1.module+el8.10.0+21354+3ad137bb
0:2.096-2.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
1:6.02-2.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:1.05-10.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:2.096-2.module+el8.10.0+24402+ce90c7a0
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

12,185
bpjstk-serviceopenshift1.0.01 of 6See more

bpjstk-service openshift 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-3.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.28-423.el8_10.1
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

35,116
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
perl@0:5.74-481.el9
0:5.74-484.el9_8
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
perl@0:5.74-481.el9
0:5.74-484.el9_8

Open the chart page →

19,051
fineractopenshift0.1.12 of 4See more

fineract openshift 0.1.1

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

7,866
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
perl@0:5.74-480.el9
0:5.74-484.el9_8

Open the chart page →

8,643
sohaopensohaVerified publisher0.1.91 of 2See more

soha opensoha 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,781
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

15,602
terminalsopen-webui0.7.02 of 2See more

terminals open-webui 0.7.0

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/open-webui/terminals:latest5d2fd44366a4
perl@5.40.1-6
5.40.1-6+deb13u1
ghcr.io/open-webui/terminals-operator:latest6287ce8be502
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,046
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

36,252
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
perl@5.18.2-2ubuntu1.4
5.18.2-2ubuntu1.7+esm8

Open the chart page →

26,364
hiveopstty0.1.91 of 4See more

hive opstty 0.1.9

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,550
grrosdfir-infrastructureVerified publisher1.0.32 of 5See more

grr osdfir-infrastructure 1.0.3

2 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,021
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.025 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

25 of the 40 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
perl@5.36.0-7+deb12u2
no fix listed
chromadb/chroma:1.5.7fc8dc8e11fb2
perl@5.40.1-6
5.40.1-6+deb13u1
library/mariadb:11.3.2e101f9db3191
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
yetiplatform/yeti:2.9.09bcbe2650a14
perl@5.40.1-6
5.40.1-6+deb13u1
yetiplatform/yeti-frontend:2.9.0873ef15d267b
perl@5.40.1-6
5.40.1-6+deb13u1
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
perl@5.36.0-7+deb12u1
no fix listed
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/openrelik/openrelik-server:latestce1132261523
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

72,547
yetiosdfir-infrastructureVerified publisher1.0.52 of 4See more

yeti osdfir-infrastructure 1.0.5

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
perl@5.40.1-6
5.40.1-6+deb13u1
yetiplatform/yeti-frontend:latest709064278c7e
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

6,679
webot-container-kit0.1.01 of 1See more

web ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
workerot-container-kit0.1.01 of 1See more

worker ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
lens-metric-proxyowan-charts0.1.01 of 1See more

lens-metric-proxy owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,327
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

12,440
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
perl@5.36.0-7+deb12u1
no fix listed
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

27,597
p4p40.1.04 of 7See more

p4 p4 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
perl@5.26.1-6ubuntu0.6
5.26.1-6ubuntu0.7+esm3
library/mongo:5.0-focal5e15a3f014ed
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
library/rabbitmq:3.11-managementc3f70098e01d
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
mastercloudapps/planner:v1.2340a950b311b2
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8

Open the chart page →

27,702
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

19,728
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8

Open the chart page →

3,604
pagespages1.0.02 of 3See more

pages pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,242
pagespages-10.1.01 of 1See more

pages pages-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:1.04d2eb25b9225
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

10,437

Container images carrying it

2,349 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
diygod/rsshub:latest1d4b508b6357
perl@5.40.1-6
5.40.1-6+deb13u1
1
diygod/rsshub:2025-11-097a6312cac0d5
perl@5.36.0-7+deb12u3
no fix listed
1
djjudas21/alertify:0.1.0ba22be670c37
perl@5.36.0-7+deb12u2
no fix listed
1
dniel/api-posts:master45a667852f2a
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
1
dobtc/bitcoin:25.1a870f7cb1105
perl@5.36.0-7
no fix listed
1
docmost/docmost:0.96.0b56947fcfd08
perl@5.40.1-6
5.40.1-6+deb13u1
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
perl@5.40.1-6
5.40.1-6+deb13u1
1
dolibarr/dolibarr:24.0.069ec52e3b7ef
perl@5.36.0-7+deb12u3
no fix listed
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
perl@5.36.0-7+deb12u3
no fix listed
1
domainmod/domainmod:4.23.04017bfe4c597
perl@5.36.0-7
no fix listed
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
dragonflyoss/client:v0.1.82edf3e921f4e0
perl@5.36.0-7+deb12u1
no fix listed
1
dremio/dremio-oss:24.1.080ed2e3b7c43
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
1
drorivry4/rego:lateste035d49b15ca
perl@5.36.0-7+deb12u1
no fix listed
1
drpcorg/dshackle:0.54.08858fae1859d
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
1
drumsergio/genieacs:1.2.16.028244054e1bf
perl@5.36.0-7+deb12u3
no fix listed
1
dserio83/velero-api:0.3.16b3d9115fee2
perl@5.36.0-7+deb12u2
no fix listed
1
dserio83/velero-watchdog:0.1.8d5deae589229
perl@5.36.0-7+deb12u2
no fix listed
1
duck1123/cert-downloader:latest0e29f19fa67c
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
1
duck1123/lnd-fileserver:latest9d6fb247b714
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
dzikoysk/reposilite:3.6.390de4c8e6c0e
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
eceasy/cli-proxy-api:v7.3.3f9abbf3fa5fe
perl@5.36.0-7+deb12u3
no fix listed
1
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
perl@5.40.1-6
5.40.1-6+deb13u1
1
eclipseaerios/hlo-allocator:v3.0.03cc1d94cfe96
perl@5.40.1-6
5.40.1-6+deb13u1
1
eclipseaerios/hlo-data-aggregator:v3.0.0b433c2b9f5dc
perl@5.40.1-6
5.40.1-6+deb13u1
1
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
perl@5.40.1-6
5.40.1-6+deb13u1
1
eclipseaerios/hlo-fe-engine:v3.0.08ed2df4ca692
perl@5.40.1-6
5.40.1-6+deb13u1
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
perl@5.40.1-6
5.40.1-6+deb13u1
1
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
perl@5.40.1-6
5.40.1-6+deb13u1
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
perl@5.36.0-7+deb12u1
no fix listed
1
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
perl@5.40.1-6
5.40.1-6+deb13u1
1
elastic/apm-server:7.17.6c7a1c63257d0
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
elastictranscoder/media:627e21dc963ab3858c6b
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
1
elastictranscoder/media-storage:f6d861a026208b8c2359
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
1
elastiflow/flow-collector:7.26.0fee67842e16b
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
perl@5.40.1-6
5.40.1-6+deb13u1
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
emqx/ecp-ui:2.5.1e33e9816f147
perl@5.36.0-7+deb12u1
no fix listed
1
emqx/emqx:5.8.935b46f7aa7a0
perl@5.40.1-6
5.40.1-6+deb13u1
1
emqx/emqx-enterprise:6.3.03b6d9c0c4199
perl@5.40.1-6
5.40.1-6+deb13u1
1
enclavenetworks/enclave:latest0a99759300d1
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
engrmth/bnkr:2.1.06d8464e6f0e8
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
1
envoyproxy/envoy:v1.30.92956bd9de830
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
envoyproxy/envoy:v1.33.056da5afd7df3
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
envoyproxy/envoy:v1.31-latestcaa5b411be16
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.8
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.