StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,398
of 17,803 indexed, latest versions
Container images
2,370
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,398 of 17,803 indexed charts deploy, on 2,370 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,332
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more38
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,398 by stars
ChartLatestAffected imagesRadar Score
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-2.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.28-423.el8_10.1
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

14,057
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

8,291
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
yandex/clickhouse-server:latest1cbf75aabe1e
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

8,606
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,295
topolvmsyself1.3.01 of 1See more

topolvm syself 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

3,612
vaultwardensyself1.0.01 of 1See more

vaultwarden syself 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
vaultwarden/server:latest094b5689ed81
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,785
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,309
nginx-charttaeseon-nginx0.1.01 of 1See more

nginx-chart taeseon-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

4,914
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:stablecb92301e719d
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,058
super-mariotechpreta0.1.11 of 1See more

super-mario techpreta 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
nirmalnaveen/supermario:latest8541a39162f3
perl@5.36.0-7
no fix listed

Open the chart page →

6,296
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,143
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

70,897
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

70,842
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.8
xeladock/nginx2:latestc259a67b1dff
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.8

Open the chart page →

105,025
tensorzerotensorzero2026.6.02 of 2See more

tensorzero tensorzero 2026.6.0

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
tensorzero/gateway:2026.6.0c939db4f27e4
perl@5.40.1-6
5.40.1-6+deb13u1
tensorzero/ui:2026.6.0f2563d54724e
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,071
supabaseteochenglim0.1.24 of 13See more

supabase teochenglim 0.1.2

4 of the 13 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/kong:latest2a8cf3b110cd
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
supabase/logflare:latest49bfe526f1b4
perl@5.40.1-6
5.40.1-6+deb13u1
supabase/realtime:latestd3aa0c86c7b3
perl@5.40.1-6
5.40.1-6+deb13u1
supabase/studio:latest94a2a9d2906e
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,862
pagestest43221.0.02 of 3See more

pages test4322 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,261
flask-contactstest-configmap1.0.12 of 3See more

flask-contacts test-configmap 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
perl@5.40.1-6
5.40.1-6+deb13u1
shashkist/flask-contacts-app:latest581de1fd6084
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,860
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,751
functionstest-helm-chart-hoanganht1k27Verified publisher0.1.11 of 1See more

functions test-helm-chart-hoanganht1k27 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
myfirstcharttest-helm-charts0.2.01 of 1See more

myfirstchart test-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,439
chatqnatest-opea1.0.08 of 11See more

chatqna test-opea 1.0.0

8 of the 11 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/chatqna:1.038c51b791efa
perl@5.36.0-7+deb12u1
no fix listed
opea/embedding-tei:1.05c9639de61c1
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed
opea/reranking-tei:1.0e48613afb191
perl@5.36.0-7+deb12u1
no fix listed
opea/retriever-redis:1.0eb746b263705
perl@5.36.0-7+deb12u1
no fix listed
redis/redis-stack:7.2.0-v91c5f43fddcdd
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

39,501
codegentest-opea1.0.04 of 5See more

codegen test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/codegen:1.058f91683892d
perl@5.36.0-7+deb12u1
no fix listed
opea/codegen-ui:1.02bee4eb66f3e
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

29,032
codetranstest-opea1.0.04 of 5See more

codetrans test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/codetrans:1.0e2436483b73d
perl@5.36.0-7+deb12u1
no fix listed
opea/codetrans-ui:1.03ef121f34610
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

28,605
docsumtest-opea1.0.04 of 5See more

docsum test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/docsum:1.03eaa91849512
perl@5.36.0-7+deb12u1
no fix listed
opea/docsum-ui:1.07f854e9bffaf
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-docsum-tgi:1.002f9e8fa5d71
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

29,080
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,243
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,278
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,777
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

5,685
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,042
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,255
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,683
teitest-opea1.0.01 of 1See more

tei test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,326
teireranktest-opea1.0.01 of 1See more

teirerank test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,326
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,423
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,418
vehicle-dashboardtest-vehi-dash0.1.03 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
library/mongo:5.0.217c81758cb295
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
library/redis:latest298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

20,436
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,017
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

10,186
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

10,115
the0the0Verified publisher0.9.82 of 9See more

the0 the0 0.9.8

2 of the 9 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mongo:7-jammy406a4fdca9fc
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

7,503
standard-applicationthebitgram1.0.121 of 1See more

standard-application thebitgram 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
perl@5.22.1-9
5.22.1-9ubuntu0.9+esm3

Open the chart page →

11,028
trafficlight-apithecampagnards0.1.11 of 1See more

trafficlight-api thecampagnards 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
thecampagnards/trafficlight-api:main7dca9d973837
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

4,411
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

25,531
pagesthiru-pages1.0.02 of 3See more

pages thiru-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,261
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,261
voyagertibuntu1.2.01 of 1See more

voyager tibuntu 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/aeharding/voyager:latest779759172676
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,464

Container images carrying it

2,370 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
perl@5.22.1-9ubuntu0.5
5.22.1-9ubuntu0.9+esm3
1
razorbladex401/dayz:latest6a4d79248e7d
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
readysettech/sqp:latest588f3507280e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
readysettech/sqp-duckdb:latest67a83203ce60
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
perl@5.40.1-6
5.40.1-6+deb13u1
1
redash/redash:25.8.000d813437db5
perl@5.36.0-7+deb12u2
no fix listed
1
redash/redash:26.3.0c5c9148f5c38
perl@5.36.0-7+deb12u3
no fix listed
1
redimp/otterwiki:2778bf30da3da
perl@5.36.0-7+deb12u3
no fix listed
1
redis/redis-stack-server:6.2.6-v251a58f32d412
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
redis/redis-stack-server:latest798ab84d9f26
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
1
redis/redis-stack-server:7.4.0-v0887cf87cc744
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
redpandadata/redpanda:latest468bd13a9f2b
perl@5.40.1-6
5.40.1-6+deb13u1
1
resouer/redis-slave:v2e2f198b49ba7
perl@5.18.2-2ubuntu1
5.18.2-2ubuntu1.7+esm8
1
resurfaceio/resurface:3.7.84d5cda2f64109
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
rezachalak/bzen-mongo:1.0.034f694325191
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
1
rhasspy/wyoming-piper:2.3.169b7f797ae3a
perl@5.36.0-7+deb12u3
no fix listed
1
rhasspy/wyoming-piper:2.5.27d39aafac409
perl@5.40.1-6
5.40.1-6+deb13u1
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
perl@5.36.0-7+deb12u3
no fix listed
1
rhasspy/wyoming-whisper:3.5.0308b7959a925
perl@5.36.0-7+deb12u3
no fix listed
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
rnwood/smtp4dev:3.6.1912304153668
perl@5.36.0-7+deb12u1
no fix listed
1
robotshop/rs-mongodb:latest119b545823cd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
rocketadmin/rocketadmin:1.17.710955ef540b9
perl@5.36.0-7+deb12u3
no fix listed
1
rocketchat/freeswitch:stablecfba5c20a5cc
perl@5.36.0-7+deb12u2
no fix listed
1
rotationalio/endeavor:1.3.0ac566baddc06
perl@5.36.0-7+deb12u3
no fix listed
1
rotationalio/genoa:1.2.03ab583519215
perl@5.36.0-7+deb12u3
no fix listed
1
rotationalio/honu:0.5.069fd30c2e31c
perl@5.36.0-7+deb12u3
no fix listed
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
perl@5.40.1-6
5.40.1-6+deb13u1
1
rraahul/test:latestbfe2c1183bc0
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
1
rrobetti/ojp:0.1.0-beta1141bd88232b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
rspamd/rspamd:4.1.4e870599c970d
perl@5.40.1-6
5.40.1-6+deb13u1
1
rstmdb/rstmdb:lateste5187f2aaace
perl@5.36.0-7+deb12u3
no fix listed
1
rtuszik/photon-docker:2.4.021549c60f9e6
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
rundeck/rundeck:3.2.74d64fe56f767
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3
1
rundeck/rundeck:3.0.16b13e8059ad72
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3
1
ryshe/terraria:latestb1c89f7f359a
perl@5.36.0-7+deb12u3
no fix listed
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
ryuunosukeds3/orbital:latest0879f7261b10
perl@5.36.0-7+deb12u2
no fix listed
1
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3ce9ce8293e4e
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
1
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9bb64bf14467d
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
1
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525799c35f9f306
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
1
santisbon/evwatcher:latestc4e994ca4540
perl@5.36.0-7
no fix listed
1
santisbon/evworker:lateste807283f8d69
perl@5.36.0-7
no fix listed
1
santisbon/speedtest:latest8ee3a1697227
perl@5.36.0-7
no fix listed
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
perl@5.36.0-7+deb12u1
no fix listed
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
perl@5.36.0-7
no fix listed
1
schemahero/schemahero-manager:0.22.11609e1a05cd3
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.