StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,409
of 17,790 indexed, latest versions
Container images
2,391
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,409 of 17,790 indexed charts deploy, on 2,391 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,352
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more39
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,409 by stars
ChartLatestAffected imagesRadar Score
static-sitepodzone-chartsVerified publisher0.1.11 of 2See more

static-site podzone-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
perl@5.36.0-7
no fix listed

Open the chart page →

6,586
agentpolyaxon2.16.43 of 4See more

agent polyaxon 2.16.4

3 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
perl@5.40.1-6
5.40.1-6+deb13u1
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
perl@5.40.1-6
5.40.1-6+deb13u1
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,254
polyaxonpolyaxon2.16.44 of 5See more

polyaxon polyaxon 2.16.4

4 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
perl@5.36.0-7+deb12u1
no fix listed
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
perl@5.40.1-6
5.40.1-6+deb13u1
polyaxon/polyaxon-api:2.16.42b55c3265a90
perl@5.40.1-6
5.40.1-6+deb13u1
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

13,995
beylaportefaix-hub0.1.01 of 1See more

beyla portefaix-hub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
grafana/beyla:1.3.336d07f8d276e
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,693
quickwitportefaix-hub0.1.11 of 1See more

quickwit portefaix-hub 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.1d29332bdadcc
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,652
postgrespostgresVerified publisher0.1.11 of 1See more

postgres postgres 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:13.12ced3ba927f4c
perl@5.36.0-7
no fix listed

Open the chart page →

4,933
svc-postgrespostgres-fiap-lanches0.1.01 of 1See more

svc-postgres postgres-fiap-lanches 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,649
keydbpozetron0.5.31 of 1See more

keydb pozetron 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
pozetroninc/keydb:v6.0.1653ae64f29da8
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

7,017
Practica_4_helmpr04helm0.1.03 of 7See more

Practica_4_helm pr04helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
perl@5.26.1-6ubuntu0.6
5.26.1-6ubuntu0.7+esm3
library/mongo:5.0.6-focal8e70544b6c76
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
library/rabbitmq:3.9-management8a279e9396a8
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

27,659
practica-helmpractica-helm0.1.02 of 7See more

practica-helm practica-helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mongo:4.4-bionic3d0e6df9fd5b
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
slagattollas/weatherservice-practica:latest68e7f56393fc
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

28,503
pagesprasanthi1.0.02 of 3See more

pages prasanthi 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,242
prefect-agentprefectVerified publisher2024.8.301638221 of 1See more

prefect-agent prefect 2024.8.30163822

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,513
flink-kubernetes-operatorpresto-loadbalancer1.10.01 of 1See more

flink-kubernetes-operator presto-loadbalancer 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

3,319
priceapp-chartpriceapp0.1.01 of 1See more

priceapp-chart priceapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ildarmukhametzyanov/priceapp:0.115d23720a3ee
perl@5.36.0-7
no fix listed

Open the chart page →

8,241
wp-chartprojet-devops0.1.01 of 2See more

wp-chart projet-devops 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,270
prometheus-optimizerprometheus-optimizer0.2.221 of 1See more

prometheus-optimizer prometheus-optimizer 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,440
prompt-dbprompt-dbVerified publisher1.0.71 of 3See more

prompt-db prompt-db 1.0.7

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/erlkoenig91/prompt-db-backend:1.0.7ab120359810d
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,355
web-chartpsb-ktcloudlab0.1.01 of 1See more

web-chart psb-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
web-chartpsg-ktcloudlab0.1.01 of 1See more

web-chart psg-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
nginx-chartpshs-nginx0.1.01 of 1See more

nginx-chart pshs-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
flaskDiaryptj-miniproject2.1.21 of 2See more

flaskDiary ptj-miniproject 2.1.2

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
freedom98/flask:k3.0d7ce1533f297
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,088
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
perl@0:5.74-483.el9
4:5.32.1-484.el9_8

Open the chart page →

4,643
apppvillaverdeVerified publisher0.2.61 of 1See more

app pvillaverde 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.31a53fc6c27208
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,752
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
perl@5.36.0-7
no fix listed

Open the chart page →

14,628
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

12,639
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

12,639
qantas-apiqantas-helm0.1.01 of 3See more

qantas-api qantas-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,649
open-terminalqaoruVerified publisher0.2.41 of 1See more

open-terminal qaoru 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/open-webui/open-terminal:0.13.0-slimdec44673c865
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,055
unifiqaoruVerified publisher1.1.31 of 2See more

unifi qaoru 1.1.3

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
linuxserver/unifi-network-application:10.6.101-ls145ccadcad5c640
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

3,428
qualys-caqualys-ca-helm3.1.01 of 1See more

qualys-ca qualys-ca-helm 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
nelssec/qualys-agent-bootstrapper:v2.1.05e471f0cdeaa
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8

Open the chart page →

1,920
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,302
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

7,713
rabbitmq-stomprabbitmq-stompVerified publisher0.1.11 of 1See more

rabbitmq-stomp rabbitmq-stomp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
spy86/rabbitmq-stomp:latestea649101b9fb
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3

Open the chart page →

3,036
nginx-chartrabsnginx0.1.01 of 1See more

nginx-chart rabsnginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.276784fb0834aa
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

4,479
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

21,291
app-configradar-baseVerified publisher1.7.21 of 1See more

app-config radar-base 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,080
catalog-serverradar-baseVerified publisher0.9.31 of 1See more

catalog-server radar-base 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,462
data-dashboard-backendradar-baseVerified publisher0.6.21 of 1See more

data-dashboard-backend radar-base 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,064
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
perl@5.40.1-7build1
5.40.1-7ubuntu0.3

Open the chart page →

3,226
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,328
radar-integrationradar-baseVerified publisher0.9.01 of 1See more

radar-integration radar-base 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.4

Open the chart page →

2,899
radar-outputradar-baseVerified publisher1.2.101 of 1See more

radar-output radar-base 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,509
radar-push-endpointradar-baseVerified publisher0.6.81 of 2See more

radar-push-endpoint radar-base 0.6.8

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
radarbase/radar-push-endpoint:0.4.0e1758508e033
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

3,062
radar-upload-connect-backendradar-baseVerified publisher0.9.11 of 1See more

radar-upload-connect-backend radar-base 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,577
s3-proxyradar-baseVerified publisher0.6.01 of 1See more

s3-proxy radar-base 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,782
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
perl@0:5.74-512.2.el10_0
0:5.74-515.el10_2

Open the chart page →

1,889
pagesranjinigogga1.0.02 of 3See more

pages ranjinigogga 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,242
rawfile-localpvrawfile0.15.21 of 6See more

rawfile-localpv rawfile 0.15.2

1 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
openebs/rawfile-localpv:v0.15.2a39ef27ea28b
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,897
rdfoxrdfox-helm-chart0.1.22 of 2See more

rdfox rdfox-helm-chart 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
oxfordsemantic/rdfox:5.6db17910eb855
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
oxfordsemantic/rdfox-init:5.6baf570ff968d
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

12,884
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

15,570

Container images carrying it

2,391 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
perl@5.36.0-7+deb12u3
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
perl@5.36.0-7+deb12u3
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
perl@5.36.0-7+deb12u1
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
perl@5.22.1-9ubuntu0.9
5.22.1-9ubuntu0.9+esm3
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
perl@5.36.0-7+deb12u3
no fix listed
3
actualbudget/actual-server:26.9.0552beab3dec8
perl@5.36.0-7+deb12u3
no fix listed
2
alazidis/kube-netlag:1.1.00e8c84152201
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
2
apache/apisix:3.18.0-ubuntu9ee5df1611f9
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
apache/nifi-registry:1.26.07cdfd8deec92
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
2
apache/rocketmq:5.4.0319cd8a81ed1
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/etcd:latest99b408c15272
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
perl@5.36.0-7+deb12u1
no fix listed
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
perl@5.36.0-7+deb12u1
no fix listed
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/redis:latest5927ff3702df
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
perl@5.36.0-7+deb12u2
no fix listed
2
bitnami/minideb:latestab4d5b45116e
perl@5.40.1-6
5.40.1-6+deb13u1
2
blockstack/stacks-core:3.2.0.0.0f79944317326
perl@5.36.0-7+deb12u2
no fix listed
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
perl@5.40.1-6
5.40.1-6+deb13u1
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
perl@5.36.0-7+deb12u1
no fix listed
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
perl@5.40.1-6
5.40.1-6+deb13u1
2
clickhouse/clickhouse-server:24.2ed9640bfff07
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
2
cribl/cribl:4.19.2044f9a5fac9a
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
dagster/user-code-example:1.13.225947f9ae481c
perl@5.40.1-6
5.40.1-6+deb13u1
2
datagrok/grok_connect:latestf5876d3aebb8
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
2
emberstack/kubernetes-reflector:10.0.6551dbd5880929
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
eqalpha/keydb:latest6537505c4235
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
perl@5.40.1-6
5.40.1-6+deb13u1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
perl@5.40.1-6
5.40.1-6+deb13u1
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.