StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,409
of 17,790 indexed, latest versions
Container images
2,391
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,409 of 17,790 indexed charts deploy, on 2,391 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,352
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more39
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,409 by stars
ChartLatestAffected imagesRadar Score
erigonethereum-helm-chartsVerified publisher2.0.21 of 2See more

erigon ethereum-helm-charts 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
erigontech/erigon:latest2252efdf9abe
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,129
lighthouseethereum-helm-chartsVerified publisher1.1.91 of 2See more

lighthouse ethereum-helm-charts 1.1.9

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
sigp/lighthouse:latest9a62bb870545
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8

Open the chart page →

1,590
rethethereum-helm-chartsVerified publisher0.1.91 of 2See more

reth ethereum-helm-charts 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/paradigmxyz/reth:latest68e76b32ad9a
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

678
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,530
iperf3eugen0.2.21 of 1See more

iperf3 eugen 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
networkstatic/iperf3:latest0592f012c636
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

829
mcrouterevryfs-ossVerified publisher0.4.01 of 2See more

mcrouter evryfs-oss 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
perl@5.26.1-6ubuntu0.6
5.26.1-6ubuntu0.7+esm3

Open the chart page →

6,511
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:latestbbd4e17f1ef8
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

4,357
cap-captcha-serverf3k-techVerified publisher0.21.01 of 1See more

cap-captcha-server f3k-tech 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
tiago2/cap:2.159f5ae4e261e
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,686
fastapi-microservice-appfast-api-microservice-app1.3.04 of 4See more

fastapi-microservice-app fast-api-microservice-app 1.3.0

4 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mongo:7.0b6421fd6d1c5
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
perl@5.36.0-7+deb12u2
no fix listed
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
perl@5.36.0-7+deb12u2
no fix listed
omkara25/simple-microservice-app-user-service:v2d62cba548580
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

9,655
federidfederidOfficialVerified publisher0.1.21 of 1See more

federid federid 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
federid/webhook:0.1.0fbfb7c6510a7
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,086
taigafermosit0.0.112 of 7See more

taiga fermosit 0.0.11

2 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
perl@5.40.1-6
5.40.1-6+deb13u1
taigaio/taiga-protected:latestfd4568a97a59
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

8,541
zabbix-server-mysqlfermosit3.0.23 of 4See more

zabbix-server-mysql fermosit 3.0.2

3 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

12,989
ferriskeyferriskey0.7.22 of 3See more

ferriskey ferriskey 0.7.2

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
perl@5.40.1-6
5.40.1-6+deb13u1
ghcr.io/ferriskey/ferriskey-api:0.7.228b6adba10f8
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,308
flink-operatorflink-operator0.1.11 of 2See more

flink-operator flink-operator 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm3

Open the chart page →

12,941
rss-bridgegabe565Verified publisher0.5.21 of 1See more

rss-bridge gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/rss-bridge/rss-bridge:latest606896116558
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,203
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

17,440
games-on-whalesgeek-cookbookVerified publisher1.8.23 of 7See more

games-on-whales geek-cookbook 1.8.2

3 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

35,444
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

15,728
lazylibrariangeek-cookbookVerified publisher7.4.21 of 1See more

lazylibrarian geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
linuxserver/lazylibrarian:version-1152df82f93d2560e233
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

11,680
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3

Open the chart page →

11,582
ombigeek-cookbookVerified publisher11.5.21 of 1See more

ombi geek-cookbook 11.5.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.8

Open the chart page →

5,178
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

8,038
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

11,602
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

10,275
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.8

Open the chart page →

13,098
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

15,917
tdarrgeek-cookbookVerified publisher4.6.22 of 2See more

tdarr geek-cookbook 4.6.2

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
haveagitgat/tdarr:2.00.181256348872ce
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
haveagitgat/tdarr_node:2.00.101e3f9328327d
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

31,185
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latest20fde516ce31
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,913
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

7,701
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.32 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

2 of the 9 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.8512bb8a21483
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
library/postgres:15.38775adb39f0d
perl@5.36.0-7
no fix listed

Open the chart page →

15,635
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,145
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mariadb:10.6.218a16204dc96c
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

6,462
openbaogitlabVerified publisher0.18.11 of 1See more

openbao gitlab 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,797
meta-monitoringgrafana1.3.01 of 2See more

meta-monitoring grafana 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
grafana/alloy:v1.4.306bdcbb51fc2
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

3,569
greenkubegreenkubeVerified publisher0.3.01 of 3See more

greenkube greenkube 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
greenkube/greenkube:0.3.00c01932282a4
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,826
ghostgroundhog2k0.212.121 of 1See more

ghost groundhog2k 0.212.12

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,022
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/grycap/im:latest06a16d4f279f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,186
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

10,169
haproxy-redis-sentinelhaproxy-redis-sentinelVerified publisher0.1.32 of 2See more

haproxy-redis-sentinel haproxy-redis-sentinel 0.1.3

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/haproxy:3.1-bookworm49a0a0d6f0b8
perl@5.36.0-7+deb12u2
no fix listed
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,317
harp-proxyharp0.8.11 of 1See more

harp-proxy harp 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
makersquad/harp-proxy:0.8.1a40dd258c527
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

6,464
hawkhawk1.1.52 of 4See more

hawk hawk 1.1.5

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
perl@5.36.0-7+deb12u1
no fix listed
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

13,676
clickstackhdx-oss-v21.1.11 of 5See more

clickstack hdx-oss-v2 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mongo:5.0.32-focal3b6c281e1c08
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

4,754
hello-helmhellok8s0.1.01 of 2See more

hello-helm hellok8s 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,022
guacamolehelmforgeVerified publisher1.5.23 of 5See more

guacamole helmforge 1.5.2

3 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1
library/postgres:17.5-bookwormfbcea1bd13b6
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

8,825
mariadbhelmforgeVerified publisher2.1.11 of 1See more

mariadb helmforge 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mariadb:12.3.3dd9b303aed4f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,924
matomohelmforgeVerified publisher2.3.01 of 3See more

matomo helmforge 2.3.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/matomo:5.13.0-apache8e6bdd396496
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,747
valkeyhelmforgeVerified publisher2.0.41 of 1See more

valkey helmforge 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2c123e3715db6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

829
vaultwardenhelmforgeVerified publisher1.14.01 of 1See more

vaultwarden helmforge 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.31587c45feaa4
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,503
mywebapphelm-nginxVerified publisher0.1.01 of 1See more

mywebapp helm-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,849
helmuphelmupVerified publisher0.1.03 of 3See more

helmup helmup 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
perl@5.36.0-7+deb12u1
no fix listed
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
perl@5.36.0-7+deb12u1
no fix listed
sirrend/helmup-notifications-service:0.1.3997866417011
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

16,574

Container images carrying it

2,391 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/mcp-hangar/mcp-hangar:2.19.14f92e139cd33
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
perl@5.36.0-7
no fix listed
1
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/nmshd/backbone-admin-cli:7.2.1f7d095c04a75
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
perl@5.36.0-7+deb12u2
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.