StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,409
of 17,790 indexed, latest versions
Container images
2,391
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,409 of 17,790 indexed charts deploy, on 2,391 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,352
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more39
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,409 by stars
ChartLatestAffected imagesRadar Score
dependency-tracknaj980.0.91 of 3See more

dependency-track naj98 0.0.9

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dependencytrack/apiserver:latestf1da63ed610a
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,489
smallandnaj980.0.51 of 1See more

smalland naj98 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3

Open the chart page →

3,026
pagesnarain1.0.02 of 3See more

pages narain 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,242
pagesnarasimha-pages1.0.02 of 3See more

pages narasimha-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,242
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
perl@5.36.0-7
no fix listed

Open the chart page →

12,876
pagesnavin-brixton1.0.02 of 3See more

pages navin-brixton 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,242
fahncsaVerified publisher1.1.11 of 1See more

fah ncsa 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
linuxserver/foldingathome:8.5.67477f6455f47
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,087
incorencsaVerified publisher1.38.02 of 29See more

incore ncsa 1.38.0

2 of the 29 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/postgresql:16.4.03ba6e6f11388
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

15,429
smilencsaVerified publisher1.1.07 of 23See more

smile ncsa 1.1.0

7 of the 23 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
perl@5.26.1-6ubuntu0.6
5.26.1-6ubuntu0.7+esm3
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
perl@5.36.0-7
no fix listed
socialmediamacroscope/image_crawler:0.1.2f508216be63c
perl@5.26.1-6ubuntu0.6
5.26.1-6ubuntu0.7+esm3
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
perl@5.36.0-7
no fix listed
socialmediamacroscope/preprocessing:0.1.3ca863306314b
perl@5.36.0-7
no fix listed
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
perl@5.36.0-7
no fix listed

Open the chart page →

109,730
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

30,326
neosyncneosyncVerified publisher0.5.412 of 3See more

neosync neosync 0.5.41

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
perl@5.36.0-7+deb12u2
no fix listed
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

7,245
apineosync-apiVerified publisher0.5.411 of 1See more

api neosync-api 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

2,849
workerneosync-workerVerified publisher0.5.411 of 1See more

worker neosync-worker 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

2,826
core-keeper-dedicatednerkho-helm-charts0.1.11 of 1See more

core-keeper-dedicated nerkho-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
escaping/core-keeper-dedicated:latest87fa79255962
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,914
netbirdnetbird1.9.01 of 4See more

netbird netbird 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

6,415
netris-dpu-agentnetrisai0.1.01 of 1See more

netris-dpu-agent netrisai 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
netrisai/bare-metal-dpu-agent:4.7.0.003c271efe749d0
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

1,574
neuralbank-stackneuralbank-stack0.1.01 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:latest4210a3296e7c
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,279
neurofaceneurofaceVerified publisher1.4.23 of 3See more

neuroface neuroface 1.4.2

3 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
perl@0:5.74-481.1.el9_6
0:5.74-484.el9_8
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
perl@0:5.74-481.1.el9_6
0:5.74-484.el9_8

Open the chart page →

7,464
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,874
agent-control-bootstrapnewrelic1.8.161 of 1See more

agent-control-bootstrap newrelic 1.8.16

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:1.24.047520b65d6b2
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

942
nfl-walletnfl-walletVerified publisher0.1.31 of 4See more

nfl-wallet nfl-wallet 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
perl@0:1.28-423.el8_10
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-3.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.28-423.el8_10.1
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

13,373
nginx-appnginx-app0.1.21 of 1See more

nginx-app nginx-app 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,344
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,344
nginx-examplengrok-ingress-helm0.3.01 of 2See more

nginx-example ngrok-ingress-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,977
ciliumnicklasfrahm-ciliumVerified publisher0.7.42 of 6See more

cilium nicklasfrahm-cilium 0.7.4

2 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

7,216
terraform-backendnimbolus0.3.21 of 2See more

terraform-backend nimbolus 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:8.2.24521b581dbdd
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,485
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,943
basenn-coVerified publisher0.1.01 of 1See more

base nn-co 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
base-jobnn-coVerified publisher0.1.01 of 4See more

base-job nn-co 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

738
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

10,290
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

6,888
firehose-corenodeifyVerified publisher1.2.62 of 2See more

firehose-core nodeify 1.2.6

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

6,558
firehose-ethereumnodeifyVerified publisher1.7.12 of 2See more

firehose-ethereum nodeify 1.7.1

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
sigp/lighthouse:v8.1.344aa773dcf27
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

5,667
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,735
app1node-web-app10.1.31 of 1See more

app1 node-web-app1 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
app2node-web-app10.1.31 of 1See more

app2 node-web-app1 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
nginx-chartnomadshk-nginx0.1.01 of 1See more

nginx-chart nomadshk-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

22,735
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,900
keycloak-helm-chartnotesprojectchart0.1.01 of 2See more

keycloak-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,649
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

6,878
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
perl@5.36.0-7
no fix listed

Open the chart page →

15,205
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
perl@5.36.0-7
no fix listed

Open the chart page →

15,279
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
perl@5.36.0-7
no fix listed

Open the chart page →

15,278
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,942
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,899
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
perl@5.18.2-2ubuntu1
5.18.2-2ubuntu1.7+esm8

Open the chart page →

41,444
fluentd-kubernetes-daemonsetnovum-rgi-charts0.1.01 of 1See more

fluentd-kubernetes-daemonset novum-rgi-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,022
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
linuxserver/codimd:latestb801bbcf6386
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

27,493

Container images carrying it

2,391 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
perl@5.36.0-7+deb12u3
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
perl@5.36.0-7+deb12u3
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
perl@5.36.0-7+deb12u1
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
perl@5.22.1-9ubuntu0.9
5.22.1-9ubuntu0.9+esm3
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
perl@5.36.0-7+deb12u3
no fix listed
3
actualbudget/actual-server:26.9.0552beab3dec8
perl@5.36.0-7+deb12u3
no fix listed
2
alazidis/kube-netlag:1.1.00e8c84152201
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
2
apache/apisix:3.18.0-ubuntu9ee5df1611f9
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
apache/nifi-registry:1.26.07cdfd8deec92
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
2
apache/rocketmq:5.4.0319cd8a81ed1
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/etcd:latest99b408c15272
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
perl@5.36.0-7+deb12u1
no fix listed
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
perl@5.36.0-7+deb12u1
no fix listed
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/redis:latest5927ff3702df
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
perl@5.36.0-7+deb12u2
no fix listed
2
bitnami/minideb:latestab4d5b45116e
perl@5.40.1-6
5.40.1-6+deb13u1
2
blockstack/stacks-core:3.2.0.0.0f79944317326
perl@5.36.0-7+deb12u2
no fix listed
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
perl@5.40.1-6
5.40.1-6+deb13u1
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
perl@5.36.0-7+deb12u1
no fix listed
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
perl@5.40.1-6
5.40.1-6+deb13u1
2
clickhouse/clickhouse-server:24.2ed9640bfff07
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
2
cribl/cribl:4.19.2044f9a5fac9a
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
dagster/user-code-example:1.13.225947f9ae481c
perl@5.40.1-6
5.40.1-6+deb13u1
2
datagrok/grok_connect:latestf5876d3aebb8
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
2
emberstack/kubernetes-reflector:10.0.6551dbd5880929
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
eqalpha/keydb:latest6537505c4235
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
perl@5.40.1-6
5.40.1-6+deb13u1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
perl@5.40.1-6
5.40.1-6+deb13u1
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.