StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,402
of 17,792 indexed, latest versions
Container images
2,380
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,402 of 17,792 indexed charts deploy, on 2,380 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,342
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more38
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,402 by stars
ChartLatestAffected imagesRadar Score
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

6,336
my-nginx-apprepo-for-helm-nginx-app0.1.01 of 1See more

my-nginx-app repo-for-helm-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,861
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,284
searxngrestic-pvc-backupVerified publisher0.1.111 of 3See more

searxng restic-pvc-backup 0.1.11

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
valkey/valkey:9.1.1-trixie64e361b630ec
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

836
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

7,446
juicepassproxyretsamedocVerified publisher2026.2.41 of 1See more

juicepassproxy retsamedoc 2026.2.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,962
otbrretsamedocVerified publisher26.9.01 of 1See more

otbr retsamedoc 26.9.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
openthread/border-router:v2026.09.07616b9d514de
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

642
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

7,138
spoolmanretsamedocVerified publisher26.9.01 of 1See more

spoolman retsamedoc 26.9.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,804
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:8.2.2f0957bcaa75f
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,633
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,876
bookinforgnu1.0.03 of 7See more

bookinfo rgnu 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.14.0ee156b8aefd6
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3
istio/examples-bookinfo-reviews-v2:1.14.0eab80bcd2132
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3
istio/examples-bookinfo-reviews-v3:1.14.01e37fca43550
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3

Open the chart page →

20,529
httpbinrgnu1.0.01 of 1See more

httpbin rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
citizenstig/httpbin:latestb81c818ccb86
perl@5.22.1-9
5.22.1-9ubuntu0.9+esm3

Open the chart page →

11,454
istio-bookinforgnu1.0.23 of 7See more

istio-bookinfo rgnu 1.0.2

3 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.14.0ee156b8aefd6
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3
istio/examples-bookinfo-reviews-v2:1.14.0eab80bcd2132
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3
istio/examples-bookinfo-reviews-v3:1.14.01e37fca43550
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3

Open the chart page →

20,529
istio-helloworldrgnu1.0.12 of 2See more

istio-helloworld rgnu 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
istio/examples-helloworld-v1:latest328b237e4fb1
perl@5.36.0-7+deb12u1
no fix listed
istio/examples-helloworld-v2:latest0a7f02b2c7c9
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,466
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.02 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
perl@0:5.74-481.1.el9_6
0:5.74-484.el9_8
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
perl@0:5.74-481.1.el9_6
0:5.74-484.el9_8

Open the chart page →

3,897
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
perl@5.36.0-7
no fix listed

Open the chart page →

4,934
kresusrm3lVerified publisher0.2.12 of 3See more

kresus rm3l 0.2.1

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
perl@5.36.0-7+deb12u2
no fix listed
bnjbvr/kresus:0.22.137e216b182c8
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

15,704
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,434
pagesroccohiggins-pages1.0.02 of 3See more

pages roccohiggins-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,262
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,328
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

6,202
rocketchat-voiprocketchat-server0.1.01 of 1See more

rocketchat-voip rocketchat-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
rocketchat/freeswitch:stablecfba5c20a5cc
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

5,766
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,703
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8

Open the chart page →

13,033
calertromholdings0.0.11 of 1See more

calert romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

4,699
devtron-enterpriseromholdings48.0.08 of 28See more

devtron-enterprise romholdings 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
perl@5.22.1-9ubuntu0.9
5.22.1-9ubuntu0.9+esm3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
perl@5.36.0-7+deb12u3
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
no fix listed

Open the chart page →

68,765
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8

Open the chart page →

4,979
devtron-operatorromholdings0.23.35 of 11See more

devtron-operator romholdings 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
no fix listed

Open the chart page →

33,219
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

11,981
migration-incluster-cdromholdings0.10.01 of 1See more

migration-incluster-cd romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,927
rommromm-helm-chartVerified publisher1.5.51 of 3See more

romm romm-helm-chart 1.5.5

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mariadb:112439dcd7d140
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

3,426
pagesronan-pages1.0.02 of 3See more

pages ronan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,262
endeavorrotationalVerified publisher1.3.12 of 2See more

endeavor rotational 1.3.1

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
rotationalio/endeavor:1.3.0ac566baddc06
perl@5.36.0-7+deb12u3
no fix listed
rotationalio/quarterdeck:0.16.00e7ad3a031dc
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,254
genoarotationalVerified publisher1.4.01 of 1See more

genoa rotational 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
rotationalio/genoa:1.2.03ab583519215
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

997
honurotationalVerified publisher0.5.31 of 1See more

honu rotational 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
rotationalio/honu:0.5.069fd30c2e31c
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,187
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,336
quarterdeckrotationalVerified publisher0.16.01 of 1See more

quarterdeck rotational 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
rotationalio/quarterdeck:0.16.00e7ad3a031dc
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,168
routehub-serverroutehub-helm1.0.12 of 3See more

routehub-server routehub-helm 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

6,978
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,536
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,742
prepull-daemonsetrstudioVerified publisher0.0.51 of 2See more

prepull-daemonset rstudio 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/ubuntu:bionic152dc042452c
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3

Open the chart page →

1,730
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8

Open the chart page →

7,583
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,657
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

27,655
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,639
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

7,470
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

2,305
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,059
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,554

Container images carrying it

2,380 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
flanksource/canary-checker-ui:v1.4.281764c84e550db
perl@5.36.0-7+deb12u1
no fix listed
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
perl@5.36.0-7+deb12u1
no fix listed
1
flashcatcloud/categraf:latest42e6ab16472e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
flashcatcloud/nightingale:8.5.1421acb36181b
perl@5.40.1-6
5.40.1-6+deb13u1
1
fluent/fluent-bit:4.0-debuge76397ef3983
perl@5.36.0-7+deb12u3
no fix listed
1
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
perl@5.40.1-6
5.40.1-6+deb13u1
1
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
perl@5.40.1-6
5.40.1-6+deb13u1
1
flyway/flyway:9.1545b5d7cdc75a
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
fnzv/dump1090:latestb3079b95c336
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
foldingathome/fah-gpu:latest5ef7742d1eb4
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
1
folioci/mod-z3950:latest2493041ce880
perl@5.40.1-6
5.40.1-6+deb13u1
1
fosrl/pangolin:latest83a55f933b4d
perl@5.36.0-7+deb12u3
no fix listed
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
1
frankescobar/allure-docker-service:latestdc171ec796d5
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
free5gmano/nextepc-mongodb:latest36f806935519
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3
1
freedom98/flask:k3.0d7ce1533f297
perl@5.36.0-7+deb12u1
no fix listed
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
1
galaxy/cloudman-server:lateste5c265fe9fcd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
galaxy/galaxy-init:v18.010267bad550e6
perl@5.18.2-2ubuntu1.4
5.18.2-2ubuntu1.7+esm8
1
galaxy/galaxy-stable:v18.018e577a626dfd
perl@5.18.2-2ubuntu1.4
5.18.2-2ubuntu1.7+esm8
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
perl@5.36.0-7+deb12u2
no fix listed
1
galexrt/extended-ceph-exporter:v1.8.05373078a3a08
perl@5.40.1-6
5.40.1-6+deb13u1
1
gchq/accumulo:2.0.1c460bb587d6d
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
1
geopython/pycsw:3.0.0-beta284662ea6b78b
perl@5.36.0-7+deb12u3
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
gethue/hue:4.11.011b649636e68
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
gethue/hue:4.10.05702b2c37ff9
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
1
gethue/hue:latest7d5c1b9f8a79
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.8
1
getsentry/relay:24.10.0ba7bf9163219
perl@5.36.0-7+deb12u1
no fix listed
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
perl@5.36.0-7+deb12u3
no fix listed
1
ghusta/postgres-world-db:latest879d0919fdcc
perl@5.40.1-6
5.40.1-6+deb13u1
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
glasskube/operator:0.12.2be5133100d63
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
1
glpi/glpi:latest4b681082a79e
perl@5.40.1-6
5.40.1-6+deb13u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.