StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,409
of 17,790 indexed, latest versions
Container images
2,391
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,409 of 17,790 indexed charts deploy, on 2,391 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,352
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more39
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,409 by stars
ChartLatestAffected imagesRadar Score
jenkinsjenkinsciOfficialVerified publisher5.9.621 of 2See more

jenkins jenkinsci 5.9.62

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jenkins/jenkins:2.568.3-jdk21c1e4c349365f
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,538
airflowapache-airflowOfficialVerified publisher1.22.01 of 4See more

airflow apache-airflow 1.22.0

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:7.2-bookworm74566c6910d1
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,218
nextcloudnextcloud9.2.61 of 1See more

nextcloud nextcloud 9.2.6

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3-apacheb97df9e0e1ee
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,584
giteagiteaOfficialVerified publisher12.7.03 of 4See more

gitea gitea 12.7.0

3 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

8,874
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.8

Open the chart page →

6,623
authentikgoauthentikOfficialVerified publisher2026.8.21 of 1See more

authentik goauthentik 2026.8.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,284
artifact-hubartifact-hubVerified publisher1.23.02 of 7See more

artifact-hub artifact-hub 1.23.0

2 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
perl@5.40.1-6
5.40.1-6+deb13u1
artifacthub/tracker:v1.23.05368d21a6e5c
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,840
alloygrafana1.12.11 of 2See more

alloy grafana 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
grafana/alloy:v1.19.2b8ec653c4423
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,151
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
perl@5.36.0-7+deb12u3
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,937
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

30,217
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,394
falcofalcosecurity9.1.01 of 3See more

falco falcosecurity 9.1.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.44.17df783d5269a
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,398
kongkongOfficialVerified publisher3.4.11 of 2See more

kong kong 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/kong:3.92a8cf3b110cd
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,186
openebsopenebsOfficialVerified publisher4.6.12 of 35See more

openebs openebs 4.6.1

2 of the 35 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.4
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

24,128
backstagebackstageOfficialVerified publisher2.10.11 of 1See more

backstage backstage 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/backstage/backstage:latest792e262ea504
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,217
rediscloudpirates-redisVerified publisher0.35.01 of 1See more

redis cloudpirates-redis 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

978
qdrantqdrantOfficialVerified publisher1.19.11 of 1See more

qdrant qdrant 1.19.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.19.112364fe851b9
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

829
apisixapisix2.17.02 of 3See more

apisix apisix 2.17.0

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
apache/apisix:3.18.0-ubuntu9ee5df1611f9
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
bitnamilegacy/etcd:latest99b408c15272
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

3,118
dagsterdagsterVerified publisher1.13.222 of 5See more

dagster dagster 1.13.22

2 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dagster/dagster-celery-k8s:1.13.22e29a64392e12
perl@5.40.1-6
5.40.1-6+deb13u1
dagster/user-code-example:1.13.225947f9ae481c
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,510
zabbixzabbix-communityVerified publisher7.1.05 of 5See more

zabbix zabbix-community 7.1.0

5 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
perl@5.40.1-6
5.40.1-6+deb13u1
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

13,880
keycloakcloudpirates-keycloakVerified publisher0.21.372 of 3See more

keycloak cloudpirates-keycloak 0.21.37

2 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
perl@5.40.1-6
5.40.1-6+deb13u1
library/postgres:18.64ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,428
fluentdfluent0.6.01 of 1See more

fluentd fluent 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,022
netdatanetdataVerified publisher3.7.1731 of 1See more

netdata netdata 3.7.173

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
netdata/netdata:v2.11.0c45c71eb23ff
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,131
node-problem-detectordeliveryheroVerified publisher2.4.11 of 1See more

node-problem-detector deliveryhero 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,984
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,399
vaultwardengissilabs1.4.21 of 1See more

vaultwarden gissilabs 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,766
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
perl@5.26.1-6ubuntu0.6
5.26.1-6ubuntu0.7+esm3

Open the chart page →

5,560
valkeyvalkeyVerified publisher0.12.01 of 1See more

valkey valkey 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2475ee65cc75c
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

829
postgrescloudpirates-postgresVerified publisher0.20.51 of 1See more

postgres cloudpirates-postgres 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.64ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,649
openldap-stack-hahelm-openldapVerified publisher4.3.32 of 5See more

openldap-stack-ha helm-openldap 4.3.3

2 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jpgouin/openldap:2.6.9-fixbfdd0088c776
perl@5.36.0-7+deb12u1
no fix listed
library/debian:latestf324c7ff5432
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,968
zammadzammadOfficialVerified publisher18.2.13 of 5See more

zammad zammad 18.2.1

3 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
perl@5.40.1-6
5.40.1-6+deb13u1
library/postgres:18.4a02db8cac496
perl@5.40.1-6
5.40.1-6+deb13u1
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

6,346
chaos-meshchaos-meshVerified publisher2.8.42 of 4See more

chaos-mesh chaos-mesh 2.8.4

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

6,415
csi-driver-nfscsi-driver-nfsVerified publisher4.13.41 of 6See more

csi-driver-nfs csi-driver-nfs 4.13.4

1 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,391
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.8

Open the chart page →

9,197
reflectoremberstackVerified publisher10.0.651 of 1See more

reflector emberstack 10.0.65

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
emberstack/kubernetes-reflector:10.0.6551dbd5880929
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

700
grafana-agentgrafana0.44.21 of 2See more

grafana-agent grafana 0.44.2

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
grafana/agent:v0.44.23364714a2f64
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

3,526
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
milvusdb/milvus:v2.2.13a3a55e1c1497
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

32,420
mesherymesheryOfficialVerified publisher1.0.701 of 1See more

meshery meshery 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,438
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

10,695
penpotpenpotOfficialVerified publisher1.9.02 of 4See more

penpot penpot 1.9.0

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
penpotapp/mcp:2.17.284f3f07ead11
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

4,405
signozsignoz0.141.11 of 5See more

signoz signoz 0.141.1

1 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.972aa1e4c1ec5
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

7,607
weblateweblateOfficialVerified publisher0.5.363 of 3See more

weblate weblate 0.5.36

3 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/redis:latest5927ff3702df
perl@5.36.0-7+deb12u2
no fix listed
weblate/weblate:2026.9.1.0990720d1737a
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

6,787
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,817
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.64ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,649
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,728
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
perl@5.36.0-7
no fix listed

Open the chart page →

4,819
difydoubanVerified publisher0.10.03 of 6See more

dify douban 0.10.0

3 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
perl@5.36.0-7+deb12u1
no fix listed
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

19,544
dragonflydragonflyVerified publisher1.8.41 of 3See more

dragonfly dragonfly 1.8.4

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.4a1b52779c4dd
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,830
secrets-store-csi-driversecret-store-csi-driver1.6.11 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,802
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,592

Container images carrying it

2,391 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/wittdennis/homeassistant-otbr:4.2.31b53b0b3488e
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
perl@5.36.0-7
no fix listed
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/wrenix/autopush-rs/autoconnect:1.84.285f93ced88b2
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/wrenix/autopush-rs/autoendpoint:1.84.2d95e9a124eed
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/yourls/yourls:1.10.69b220ea83329
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.1da0b5eb7721a
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
perl@5.36.0-7+deb12u3
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/redis47200b041382
perl@5.36.0-7+deb12u3
no fix listed
1
public.ecr.aws/aktosecurity/redis:latestV8.6.2832d7785830f
perl@5.40.1-6
5.40.1-6+deb13u1
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/datadog/cloudprem:v0.1.33bda08753668d
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
perl@5.40.1-6
5.40.1-6+deb13u1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
perl@5.36.0-7+deb12u1
no fix listed
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.8
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
perl@5.40.1-6+e4
5.40.1-6+e15
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
perl@5.36.0-7+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
perl@5.36.0-7+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
perl@5.36.0-7+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
perl@5.36.0-7+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
perl@5.36.0-7
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
perl@5.36.0-7+deb12u3
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.