StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,398
of 17,803 indexed, latest versions
Container images
2,370
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,398 of 17,803 indexed charts deploy, on 2,370 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,332
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more38
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,398 by stars
ChartLatestAffected imagesRadar Score
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-2.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.28-423.el8_10.1
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

14,057
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

8,291
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
yandex/clickhouse-server:latest1cbf75aabe1e
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

8,606
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,295
topolvmsyself1.3.01 of 1See more

topolvm syself 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

3,612
vaultwardensyself1.0.01 of 1See more

vaultwarden syself 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
vaultwarden/server:latest094b5689ed81
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,785
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,309
nginx-charttaeseon-nginx0.1.01 of 1See more

nginx-chart taeseon-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

4,914
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:stablecb92301e719d
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,058
super-mariotechpreta0.1.11 of 1See more

super-mario techpreta 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
nirmalnaveen/supermario:latest8541a39162f3
perl@5.36.0-7
no fix listed

Open the chart page →

6,296
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,143
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

70,897
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

70,842
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.8
xeladock/nginx2:latestc259a67b1dff
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.8

Open the chart page →

105,025
tensorzerotensorzero2026.6.02 of 2See more

tensorzero tensorzero 2026.6.0

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
tensorzero/gateway:2026.6.0c939db4f27e4
perl@5.40.1-6
5.40.1-6+deb13u1
tensorzero/ui:2026.6.0f2563d54724e
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,071
supabaseteochenglim0.1.24 of 13See more

supabase teochenglim 0.1.2

4 of the 13 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/kong:latest2a8cf3b110cd
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
supabase/logflare:latest49bfe526f1b4
perl@5.40.1-6
5.40.1-6+deb13u1
supabase/realtime:latestd3aa0c86c7b3
perl@5.40.1-6
5.40.1-6+deb13u1
supabase/studio:latest94a2a9d2906e
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,862
pagestest43221.0.02 of 3See more

pages test4322 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,261
flask-contactstest-configmap1.0.12 of 3See more

flask-contacts test-configmap 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
perl@5.40.1-6
5.40.1-6+deb13u1
shashkist/flask-contacts-app:latest581de1fd6084
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,860
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,751
functionstest-helm-chart-hoanganht1k27Verified publisher0.1.11 of 1See more

functions test-helm-chart-hoanganht1k27 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
myfirstcharttest-helm-charts0.2.01 of 1See more

myfirstchart test-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,439
chatqnatest-opea1.0.08 of 11See more

chatqna test-opea 1.0.0

8 of the 11 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/chatqna:1.038c51b791efa
perl@5.36.0-7+deb12u1
no fix listed
opea/embedding-tei:1.05c9639de61c1
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed
opea/reranking-tei:1.0e48613afb191
perl@5.36.0-7+deb12u1
no fix listed
opea/retriever-redis:1.0eb746b263705
perl@5.36.0-7+deb12u1
no fix listed
redis/redis-stack:7.2.0-v91c5f43fddcdd
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

39,501
codegentest-opea1.0.04 of 5See more

codegen test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/codegen:1.058f91683892d
perl@5.36.0-7+deb12u1
no fix listed
opea/codegen-ui:1.02bee4eb66f3e
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

29,032
codetranstest-opea1.0.04 of 5See more

codetrans test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/codetrans:1.0e2436483b73d
perl@5.36.0-7+deb12u1
no fix listed
opea/codetrans-ui:1.03ef121f34610
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

28,605
docsumtest-opea1.0.04 of 5See more

docsum test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/docsum:1.03eaa91849512
perl@5.36.0-7+deb12u1
no fix listed
opea/docsum-ui:1.07f854e9bffaf
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-docsum-tgi:1.002f9e8fa5d71
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

29,080
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,243
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,278
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,777
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

5,685
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,042
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,255
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,683
teitest-opea1.0.01 of 1See more

tei test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,326
teireranktest-opea1.0.01 of 1See more

teirerank test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,326
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,423
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,418
vehicle-dashboardtest-vehi-dash0.1.03 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
library/mongo:5.0.217c81758cb295
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm3
library/redis:latest298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

20,436
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,017
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

10,186
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

10,115
the0the0Verified publisher0.9.82 of 9See more

the0 the0 0.9.8

2 of the 9 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mongo:7-jammy406a4fdca9fc
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

7,503
standard-applicationthebitgram1.0.121 of 1See more

standard-application thebitgram 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
perl@5.22.1-9
5.22.1-9ubuntu0.9+esm3

Open the chart page →

11,028
trafficlight-apithecampagnards0.1.11 of 1See more

trafficlight-api thecampagnards 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
thecampagnards/trafficlight-api:main7dca9d973837
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

4,411
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

25,531
pagesthiru-pages1.0.02 of 3See more

pages thiru-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,261
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,261
voyagertibuntu1.2.01 of 1See more

voyager tibuntu 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/aeharding/voyager:latest779759172676
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,464

Container images carrying it

2,370 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
perl@5.40.1-6
5.40.1-6+deb13u1
1
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
perl@5.40.1-6
5.40.1-6+deb13u1
1
thingsboard/tbmq-node:2.4.070661025dba5
perl@5.40.1-6
5.40.1-6+deb13u1
1
thingsboard/tb-postgres:latest2d17e4e36edc
perl@5.36.0-7+deb12u3
no fix listed
1
thmmniii/fbs-core:v1.27.15438517d9fc2
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.8
1
thongngo3301/stakefish:latesta341af5976e3
perl@5.36.0-7
no fix listed
1
tiago2/cap:2.159f5ae4e261e
perl@5.40.1-6
5.40.1-6+deb13u1
1
tianon/exim4:latestb489049cdbca
perl@5.40.1-6
5.40.1-6+deb13u1
1
tibyandocker/serviceexample:latesta4ad592cea84
perl@5.36.0-7+deb12u3
no fix listed
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.8
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
perl@5.22.1-9ubuntu0.2
5.22.1-9ubuntu0.9+esm3
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
perl@5.40.1-6
5.40.1-6+deb13u1
1
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
perl@5.40.1-6
5.40.1-6+deb13u1
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
perl@5.40.1-6
5.40.1-6+deb13u1
1
tpdock/freeradius:2.2.93da600c95a49
perl@5.22.1-9ubuntu0.2
5.22.1-9ubuntu0.9+esm3
1
treskon/portrait:DEV-latest88e813f22347
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
perl@5.36.0-7+deb12u1
no fix listed
1
trinodb/trino:405ee80ab5eeab2
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
1
trueosiris/vrising:latest9356f98ad561
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
1
tussanakorndev/kube-pod-alerts:1.0.5216fdadadf9a
perl@5.40.1-6
5.40.1-6+deb13u1
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
typesense/typesense:0.25.1035ccfbc3fd8
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8
1
typesense/typesense:0.23.03accb727cbe2
perl@5.22.1-9ubuntu0.9
5.22.1-9ubuntu0.9+esm3
1
typesense/typesense:30.191604dc128e2
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
1
typesense/typesense:28.0.rc35dea1b62b7b6e
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
ubuntu/squid:5.2-22.04_beta723891b5bc74
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
perl@5.36.0-7+deb12u2
no fix listed
1
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
v3xl/kubesend:0.1.06f62ca96be82
perl@5.36.0-7+deb12u2
no fix listed
1
valkey/valkey:8.1.61f84517eca8e
perl@5.40.1-6
5.40.1-6+deb13u1
1
valkey/valkey:9.0.54c64dfeae602
perl@5.40.1-6
5.40.1-6+deb13u1
1
valkey/valkey:8.0.1c5d4f082b76d
perl@5.36.0-7+deb12u1
no fix listed
1
vaultwarden/server:1.35.443498a94b22f
perl@5.40.1-6
5.40.1-6+deb13u1
1
vaultwarden/server:1.34.384fd8a47f58d
perl@5.36.0-7+deb12u2
no fix listed
1
vaultwarden/server:1.35.79a8eec71f4a5
perl@5.40.1-6
5.40.1-6+deb13u1
1
vcnngr/telegram-login:latest1a849a997b6d
perl@5.36.0-7+deb12u2
no fix listed
1
vcnngr/telegram-rebot:latest30f1f05e57a6
perl@5.36.0-7+deb12u2
no fix listed
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
perl@5.36.0-7+deb12u2
no fix listed
1
venturenox/redis:latest83b471c193ba
perl@5.36.0-7+deb12u1
no fix listed
1
vexorian/dizquetv:1.4.37e2b99844a5c
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
1
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
perl@5.26.1-6ubuntu0.6
5.26.1-6ubuntu0.7+esm3
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
perl@0:1.28-420.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
0:1.28-423.el8_10.1
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
perl@5.36.0-7+deb12u1
no fix listed
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-2.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.28-423.el8_10.1
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb
1
vlebediantsev/notes-admin-front:latest007c6670ff48
perl@5.36.0-7
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.