StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,409
of 17,790 indexed, latest versions
Container images
2,391
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,409 of 17,790 indexed charts deploy, on 2,391 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,352
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more39
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,409 by stars
ChartLatestAffected imagesRadar Score
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

4,277
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,937
gitlab-omnibusslamdev0.1.61 of 2See more

gitlab-omnibus slamdev 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
daedalusproject/base_kubectl:latest6f72b5119eda
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

2,851
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,945
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3

Open the chart page →

46,047
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
perl@5.40.1-6
5.40.1-6+deb13u1
valkey/valkey:8.1.61f84517eca8e
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,040
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

14,550
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,330
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

7,204
pubsubplussolaceVerified publisher3.10.01 of 1See more

pubsubplus solace 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
solace/solace-pubsub-standard:latest8e8ad105595e
perl@0:1.01-481.1.el9_6
0:1.01-484.el9_8

Open the chart page →

285
pubsubplus-devsolaceVerified publisher3.10.01 of 1See more

pubsubplus-dev solace 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
solace/solace-pubsub-standard:latest8e8ad105595e
perl@0:1.01-481.1.el9_6
0:1.01-484.el9_8

Open the chart page →

285
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
perl@5.36.0-7+deb12u3
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,604
rabbitmqsolidchartsVerified publisher0.7.51 of 2See more

rabbitmq solidcharts 0.7.5

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.5-managementffd1b50c522a
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,045
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,699
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

10,450
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8

Open the chart page →

2,624
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,694
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

13,536
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

25,005
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
alazidis/stornx:1.1.1602d4f7f090c
perl@5.36.0-7+deb12u3
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

11,735
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,881
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
kong/kong:3.9.16addf50e6bd8
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
supabase/edge-runtime:v1.74.02781daf92394
perl@5.36.0-7+deb12u3
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
perl@5.36.0-7+deb12u3
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
perl@5.36.0-7+deb12u3
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

18,327
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

2,142
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,263
mumblesyntaxerror404Verified publisher1.0.41 of 1See more

mumble syntaxerror404 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,143
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/haproxy:3.2de601ccc9a79
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

846
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
perl@5.36.0-7
no fix listed

Open the chart page →

9,119
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
perl@5.36.0-7
no fix listed

Open the chart page →

9,119
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

13,017
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,075
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
perl@5.40.1-6
5.40.1-6+deb13u1
kixote/typemilldigest-pinned628f79a08cc7
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,474
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8

Open the chart page →

1,911
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

3,806
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

3,806
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

12,672
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
perl@5.40.1-6
5.40.1-6+deb13u1
taigaio/taiga-protected:latestfd4568a97a59
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

9,193
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,339
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,318
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,063
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

5,259
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

26,848
phpipamvquieVerified publisher1.0.31 of 3See more

phpipam vquie 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mariadb:10.11.21c33370a599c
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8

Open the chart page →

7,072
waldurwaldur-chartsVerified publisher8.1.22 of 3See more

waldur waldur-charts 8.1.2

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
perl@5.40.1-6
5.40.1-6+deb13u1
opennode/waldur-mastermind:8.1.24c82b15d9042
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,901
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

15,986
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
perl@5.18.2-2ubuntu1
5.18.2-2ubuntu1.7+esm8

Open the chart page →

41,444
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

7,903
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

7,764
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

8,320

Container images carrying it

2,391 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
perl@5.40.1-6
5.40.1-6+deb13u1
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
perl@5.40.1-6
5.40.1-6+deb13u1
1
stackstorm/st2actionrunner:3.888235ba70cad
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2api:3.86f56d239d280
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2auth:3.833ecfda16608
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2notifier:3.8f190a6212195
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2rulesengine:3.8259503496ff9
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2scheduler:3.8b1de2055c362
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2stream:3.81c8904a3bf67
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2timersengine:3.81bf35bfaf00c
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2web:3.809989a26c8b7
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stackstorm/st2workflowengine:3.819fdfffdbba8
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
stalwartlabs/stalwart:v0.16.1425001929f36a
perl@5.40.1-6
5.40.1-6+deb13u1
1
stalwartlabs/stalwart:v0.16.22388dcb75a707
perl@5.40.1-6
5.40.1-6+deb13u1
1
stalwartlabs/stalwart:v0.16.2074ca4f7f6885
perl@5.40.1-6
5.40.1-6+deb13u1
1
stalwartlabs/stalwart:v0.15.5dcf575db2d53
perl@5.40.1-6
5.40.1-6+deb13u1
1
stashapp/stash:latest24dbd7607174
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
stashapp/stash-box:latesta534c8afdf39
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
statcan/ckan:2.93921305425b8
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
statusim/nimbus-eth2:multiarch-latest6ccd9d382885
perl@5.36.0-7+deb12u3
no fix listed
1
steamcmd/steamcmd:latest5028a25268e7
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
strangebee/thehive:5.8.0-1a7f7b05fba24
perl@5.36.0-7+deb12u3
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
structurizr/onpremises:2025.11.094b5ffb5119c8
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
substratusai/verba:v0.4.0-baseURL261695be635eb
perl@5.36.0-7+deb12u1
no fix listed
1
supabase/edge-runtime:v1.74.02781daf92394
perl@5.36.0-7+deb12u3
no fix listed
1
supabase/edge-runtime:v1.59.0eff9c554d649
perl@5.36.0-7+deb12u1
no fix listed
1
supabase/logflare:latest49bfe526f1b4
perl@5.40.1-6
5.40.1-6+deb13u1
1
supabase/postgres-meta:v0.96.6a84cc713585e
perl@5.36.0-7+deb12u3
no fix listed
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
perl@5.36.0-7+deb12u1
no fix listed
1
supabase/realtime:v2.102.3aa1c92c0cf32
perl@5.36.0-7+deb12u3
no fix listed
1
supabase/realtime:v2.33.8d207e6e23ad3
perl@5.36.0-7+deb12u1
no fix listed
1
supabase/realtime:latestd3aa0c86c7b3
perl@5.40.1-6
5.40.1-6+deb13u1
1
supabase/studio:20241021-9f9b08326d8070c55e9
perl@5.36.0-7+deb12u1
no fix listed
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
perl@5.36.0-7+deb12u3
no fix listed
1
supabase/studio:latest94a2a9d2906e
perl@5.36.0-7+deb12u3
no fix listed
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
perl@5.36.0-7+deb12u1
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
swimmwatch/cloakbrowser-mcp:1.13.0d48c705a58c8
perl@5.36.0-7+deb12u3
no fix listed
1
sysnet4admin/colosseum-agg:logbc25b152d88e
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
1
sysnet4admin/colosseum-cms:loge74b43c7f492
perl@5.36.0-7+deb12u2
no fix listed
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
perl@5.36.0-7+deb12u2
no fix listed
1
sysnet4admin/colosseum-rwd:log74ded2d92f07
perl@5.40.1-6
5.40.1-6+deb13u1
1
tautulli/tautulli:latest670e68dd9efc
perl@5.40.1-6
5.40.1-6+deb13u1
1
tchiotludo/akhq:0.28.0c2824dc2ae44
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.