StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,395
of 17,797 indexed, latest versions
Container images
2,368
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,395 of 17,797 indexed charts deploy, on 2,368 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,330
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more38
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,395 by stars
ChartLatestAffected imagesRadar Score
routergroundcover1.12.3752See more

router groundcover 1.12.375

2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.8
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
perl@5.40.1-6+e4
5.40.1-6+e15

Open the chart page →

librechat-exporterhajowielandVerified publisher1.0.01 of 1See more

librechat-exporter hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

2,308
rag-apihajowielandVerified publisher1.0.01 of 1See more

rag-api hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,723
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,434
hatchet-apihatchetOfficialVerified publisher0.19.01 of 4See more

hatchet-api hatchet 0.19.0

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,707
hatchet-hahatchetOfficialVerified publisher0.19.03 of 8See more

hatchet-ha hatchet 0.19.0

3 of the 8 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
perl@5.36.0-7+deb12u2
no fix listed
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

7,447
hatchet-stackhatchetOfficialVerified publisher0.19.03 of 8See more

hatchet-stack hatchet 0.19.0

3 of the 8 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
perl@5.36.0-7+deb12u2
no fix listed
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

7,447
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

9,233
web-charthcpark-ktcloudlab0.1.01 of 1See more

web-chart hcpark-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,861
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3

Open the chart page →

6,758
heliconehelicone0.1.423 of 14See more

helicone helicone 0.1.42

3 of the 14 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
perl@5.36.0-7
no fix listed

Open the chart page →

25,250
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,696
test-apphellnet0.1.11 of 1See more

test-app hellnet 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,861
hello-worldhello-world-pponyVerified publisher0.3.01 of 1See more

hello-world hello-world-ppony 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.25.49ff236ed47fe
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,880
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
perl@5.26.1-6ubuntu0.6
5.26.1-6ubuntu0.7+esm3

Open the chart page →

10,730
my_web1helm-chart-by-piyush0.1.01 of 1See more

my_web1 helm-chart-by-piyush 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/httpd:latest979c38c2228d
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,715
pageshelm-chart-repos-camden1.0.02 of 3See more

pages helm-chart-repos-camden 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

20,262
esphomehelm-chart-roeiVerified publisher2025.3.01 of 1See more

esphome helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
esphome/esphome:2025.3.0def8b6e4f517
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

6,018
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

3,835
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
iofog/router:2.0.17260cf861479
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

24,205
nginx-charthelm-chart-sample-app0.1.01 of 1See more

nginx-chart helm-chart-sample-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
rraahul/test:latestbfe2c1183bc0
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8

Open the chart page →

4,609
kube-downscalerhelm-charts-nr0.7.61 of 1See more

kube-downscaler helm-charts-nr 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
perl@5.36.0-7
no fix listed

Open the chart page →

4,319
locusthelm-charts-nr0.32.41 of 1See more

locust helm-charts-nr 0.32.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,824
node-problem-detectorhelm-charts-nr2.3.171 of 1See more

node-problem-detector helm-charts-nr 2.3.17

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,470
supersethelm-charts-nr1.1.31 of 1See more

superset helm-charts-nr 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,332
hello-world-charthelm-chart-test-hello-world0.1.01 of 1See more

hello-world-chart helm-chart-test-hello-world 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,861
mywebhelmchartwebapp0.0.51 of 1See more

myweb helmchartwebapp 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/httpd:latest979c38c2228d
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,715
my-apphelm-demo85640.2.71 of 2See more

my-app helm-demo8564 0.2.7

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,861
chart-bookhelm-deploy-book0.1.01 of 3See more

chart-book helm-deploy-book 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dannielkil/book-frontend:latest937993927694
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,165
affinehelmforgeVerified publisher1.0.03 of 3See more

affine helmforge 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1
pgvector/pgvector:0.8.6-pg16-bookwormccc6e83d6e35
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,115
alfiohelmforgeVerified publisher1.2.121 of 3See more

alfio helmforge 1.2.12

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,132
apachehelmforgeVerified publisher1.0.61 of 1See more

apache helmforge 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/httpd:2.4.68979c38c2228d
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,715
appwritehelmforgeVerified publisher2.0.02 of 5See more

appwrite helmforge 2.0.0

2 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
appwrite/new:1.1.96-self-hostedaf65a77db50e
perl@5.40.1-6
5.40.1-6+deb13u1
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,717
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,666
automatischhelmforgeVerified publisher1.3.72 of 4See more

automatisch helmforge 1.3.7

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,843
booklorehelmforgeVerified publisher2.0.11 of 3See more

booklore helmforge 2.0.1

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mariadb:12.3.3dd9b303aed4f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

2,343
castopodhelmforgeVerified publisher1.2.72 of 3See more

castopod helmforge 1.2.7

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
perl@5.40.1-6
5.40.1-6+deb13u1
library/mariadb:12.3.3dd9b303aed4f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

9,524
changedetectionhelmforgeVerified publisher1.1.161 of 1See more

changedetection helmforge 1.1.16

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.5f69554198005
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,630
chiefonboardinghelmforgeVerified publisher1.1.152 of 3See more

chiefonboarding helmforge 1.1.15

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
perl@5.40.1-6
5.40.1-6+deb13u1
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

7,209
ckanhelmforgeVerified publisher1.3.84 of 6See more

ckan helmforge 1.3.8

4 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ckan/ckan-base:2.12.087ecf3f27ad6
perl@5.36.0-7+deb12u3
no fix listed
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,064
countlyhelmforgeVerified publisher1.2.62 of 3See more

countly helmforge 1.2.6

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
library/mongo:8.3.85211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

18,967
dawarichhelmforgeVerified publisher1.0.12 of 4See more

dawarich helmforge 1.0.1

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1
postgis/postgis:18-3.67e00e8c3539f
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,497
discount-bandithelmforgeVerified publisher2.0.81 of 3See more

discount-bandit helmforge 2.0.8

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
cybrarist/discount-bandit:v4.0.4e9e2447ac666
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

30,281
druidhelmforgeVerified publisher1.3.62 of 4See more

druid helmforge 1.3.6

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1
library/zookeeper:3.9.5f258365d4882
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8

Open the chart page →

8,660
drupalhelmforgeVerified publisher1.2.131 of 2See more

drupal helmforge 1.2.13

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,902
entehelmforgeVerified publisher1.0.22 of 4See more

ente helmforge 1.0.2

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,283
fastmcp-serverhelmforgeVerified publisher1.7.41 of 1See more

fastmcp-server helmforge 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.11.2fcb7017327d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,306
generichelmforgeVerified publisher3.1.51 of 1See more

generic helmforge 3.1.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.31.505b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,861
ghosthelmforgeVerified publisher1.2.71 of 3See more

ghost helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,493
hoppscotchhelmforgeVerified publisher1.1.111 of 2See more

hoppscotch helmforge 1.1.11

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,094

Container images carrying it

2,368 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/containeroo/filesystem-exporter:v1.5.2a66121e16d4e
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/cosanet/cosanet:1.0.098cb5d9fa215
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/dakera-ai/dakera:0.11.101af610992a416
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/dakera-ai/dakera-mcp:0.10.11a3d48418b14a
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/damap-org/damap-frontend:5.0.1609f48af4efc
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/danielgines/brightdata-exporter:0.2.176920d17cf6ff
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/dask/dask:2024.1.0080150de7d86
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/defguard/defguard:2.1.0df2e31d3b4f5
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/defguard/defguard-proxy:2.1.08765a28e383e
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/defguard/gateway:2.1.0738b2b6f413b
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/developmentseed/titiler:latest0f31f8b0441b
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
perl@5.36.0-7+deb12u2
no fix listed
1
ghcr.io/deven96/ahnlich-db:latest45d8b5aab491
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/dgtlmoon/changedetection.io:0.60.3:latestecacd9fd0c66
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/dgtlmoon/changedetection.io:0.60.5f69554198005
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/donkie/spoolman:0.24.042135965c42d
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/dragoangel/mcrouter:v2026.06.29.0042afcffe67d0
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/drakkan/sftpgo:v2.7.46cb60f08fede
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
1
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/enderdash-com/enderdash-agent:latest8525a1a67958
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/erlkoenig91/prompt-db-backend:1.0.7ab120359810d
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
perl@5.40.1-6
5.40.1-6+deb13u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.