StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,396
of 17,790 indexed, latest versions
Container images
2,371
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,396 of 17,790 indexed charts deploy, on 2,371 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,334
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more37
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,396 by stars
ChartLatestAffected imagesRadar Score
memcachedkubelauncherVerified publisher0.1.321 of 1See more

memcached kubelauncher 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/memcacheddigest-pinnedb599ca6b3ff3
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

634
mysqlkubelauncherVerified publisher0.4.41 of 1See more

mysql kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnede9609bd50416
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

977
postgresqlkubelauncherVerified publisher0.4.31 of 1See more

postgresql kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinned1a27e11e5925
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,154
velero-uiotwldVerified publisher0.15.01 of 1See more

velero-ui otwld 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
otwld/velero-ui:0.10.2d1954b759e47
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,344
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2api:3.86f56d239d280
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2auth:3.833ecfda16608
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2notifier:3.8f190a6212195
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2rulesengine:3.8259503496ff9
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2scheduler:3.8b1de2055c362
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2sensorcontainer:3.8b1a338f64773
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2stream:3.81c8904a3bf67
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2timersengine:3.81bf35bfaf00c
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2web:3.809989a26c8b7
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
stackstorm/st2workflowengine:3.819fdfffdbba8
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

96,984
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
library/kong:3.8.0712e407b20ea
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
supabase/edge-runtime:v1.59.0eff9c554d649
perl@5.36.0-7+deb12u1
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
perl@5.36.0-7+deb12u1
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
perl@5.36.0-7+deb12u1
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

23,263
wekanwekanVerified publisher11.83.01See more

wekan wekan 11.83.0

1 container image this version deploys carries CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latest6cb94aa01999
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
perl@5.36.0-7+deb12u1
no fix listed
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

8,530
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,749
budibasebudibase0.0.0-master3 of 7See more

budibase budibase 0.0.0-master

3 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
perl@5.36.0-7+deb12u3
no fix listed
budibase/proxy:3.41.38d780b6ee602
perl@5.40.1-6
5.40.1-6+deb13u1
library/redis:latest298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,810
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.8

Open the chart page →

3,493
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,037
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.8

Open the chart page →

7,896
cassandrakubelauncherVerified publisher0.1.271 of 1See more

cassandra kubelauncher 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinnedb66aba320083
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,490
etcdkubelauncherVerified publisher0.4.31 of 1See more

etcd kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinned8ab954711fb9
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

806
kafkakubelauncherVerified publisher0.1.261 of 1See more

kafka kubelauncher 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned43e1085cd0a8
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,399
keycloakkubelauncherVerified publisher0.4.41 of 1See more

keycloak kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinnedafe3bd73d7cf
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,291
kubectlkubelauncherVerified publisher0.2.111 of 1See more

kubectl kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned7280594a2f18
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,255
mariadbkubelauncherVerified publisher0.5.71 of 1See more

mariadb kubelauncher 0.5.7

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mariadbdigest-pinnede25056a6ec52
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,101
mongodbkubelauncherVerified publisher0.4.51 of 1See more

mongodb kubelauncher 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinned9bc37ed78a8b
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,380
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

1,279
rabbitmqkubelauncherVerified publisher0.2.111 of 1See more

rabbitmq kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinnedff5a36a457f1
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,118
rediskubelauncherVerified publisher0.5.11 of 1See more

redis kubelauncher 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedbcd8e9a6224f
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

809
zookeeperkubelauncherVerified publisher0.2.111 of 1See more

zookeeper kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/zookeeperdigest-pinned7826e9caa461
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,027
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

3,128
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
perl@0:5.74-512.2.el10_0
0:5.74-515.el10_2

Open the chart page →

3,050
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,492
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

11,453
zillazillaOfficialVerified publisher2.4.21 of 1See more

zilla zilla 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8

Open the chart page →

1,737
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,951
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

4,281
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,024
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

4,604
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
no fix listed

Open the chart page →

31,447
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

3,645
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

5,396
ilumilumOfficialVerified publisher6.7.34 of 19See more

ilum ilum 6.7.3

4 of the 19 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/postgresql:16233f361c5819
perl@5.36.0-7+deb12u1
no fix listed
ilum/api:6.7.3624fd09528c8
perl@5.40.1-6
5.40.1-6+deb13u1
ilum/marquez:0.54.06e1d709d41f8
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

23,289
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

3,434
lakekeeperlakekeeperVerified publisher0.12.01 of 2See more

lakekeeper lakekeeper 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,935
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

7,031
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,665
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,344
netris-controllernetrisai2.8.24 of 14See more

netris-controller netrisai 2.8.2

4 of the 14 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
netrisai/controller-telescope:4.6.0.00414d82948a8b2
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
netrisai/controller-web-session-generator:0.2.0a030a31289f4
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

30,481
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,257
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

17,306
paperless-ngxpaperless-ngxVerified publisher0.3.223 of 3See more

paperless-ngx paperless-ngx 0.3.22

3 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
no fix listed
valkey/valkey:9.1.2c123e3715db6
perl@5.40.1-6
5.40.1-6+deb13u1
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

8,510
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
platform9community/api-gateway:latest40a4970de568
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
platform9community/customers-service:latest2089811e5cc6
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
platform9community/vets-service:latestd1165c94dfb3
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
platform9community/visits-service:latest8d11b50368c6
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

41,902
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

14,276
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

11,831
tbmq-clustertbmq-helm-chartOfficialVerified publisher2.1.02 of 3See more

tbmq-cluster tbmq-helm-chart 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
perl@5.40.1-6
5.40.1-6+deb13u1
thingsboard/tbmq-node:2.4.070661025dba5
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,555

Container images carrying it

2,371 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/reitermarkus/7d2d:main39953b387b61
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
perl@5.36.0-7
no fix listed
1
ghcr.io/rss-bridge/rss-bridge:latest606896116558
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/securo-finance/securo-backend:0.15.162e030110745
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/sergelogvinov/fluentd:1.19.33273d13f1e75
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
perl@5.36.0-7+deb12u2
no fix listed
1
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.8
1
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/stac-utils/stac-fastapi-pgstac:6.4.0fa35b9519abb
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/stac-utils/titiler-pgstac:3.1.0788173c5876d
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/steadybit/agent:2.4.52bc7b260e44e
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/steadybit/extension-container:v1.8.0dd31d4713ef6
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/steadybit/extension-host:v1.8.0a198ac7bc8c1
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
perl@5.36.0-7+deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.