StackRadar

CVE-2026-13221

Critical

Advisory

Published 13 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,409
of 17,790 indexed, latest versions
Container images
2,391
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 2,409 of 17,790 indexed charts deploy, on 2,391 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.18.2-2ubuntu1.7+esm8, 5.22.1-9ubuntu0.9+esm3, 5.26.1-6ubuntu0.7+esm3, 5.30.0-9ubuntu0.5+esm3+5 more2,352
perlrpm0:1.01-481.1.el9_6, 0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1+12 more0:1.01-484.el9_8, 0:1.28-423.el8_10.1, 0:5.74-475.module+el8.10.0+24767+f69b15b5, 0:5.74-484.el9_8+2 more39
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-13221UBUNTU-CVE-2026-13221RHSA-2026:67155RHSA-2026:67156RHSA-2026:67162RHSA-2026:67278RLSA-2026:67155ECHO-6100-7255-ee29
Also known as
USN-8675-1, USN-8675-2, USN-8684-1

Charts affected

2,409 by stars
ChartLatestAffected imagesRadar Score
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,723
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
diygod/rsshub:latest1d4b508b6357
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,739
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3

Open the chart page →

22,792
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

10,647
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

14,004
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

9,669
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

10,221
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

10,671
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3

Open the chart page →

11,900
gitvotegitvoteVerified publisher1.5.01 of 6See more

gitvote gitvote 1.5.0

1 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,639
apimgraviteeioVerified publisher4.12.192 of 4See more

apim graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
perl@5.40.1-6
5.40.1-6+deb13u1
graviteeio/apim-management-api:4.12.19-debian27374522cd04
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,852
nacosgujunxiang0.1.51 of 1See more

nacos gujunxiang 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
nacos/nacos-server:latest1c191c30c8cd
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3

Open the chart page →

1,827
terrariahalkeye0.4.21 of 2See more

terraria halkeye 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ryshe/terraria:latestb1c89f7f359a
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,190
netbirdhelmforgeVerified publisher1.0.102 of 4See more

netbird helmforge 1.0.10

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1
netbirdio/netbird-server:0.78.13086534361a1
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

3,035
redishelmforgeVerified publisher3.0.01 of 1See more

redis helmforge 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

978
typesensehmphuVerified publisher0.1.61 of 1See more

typesense hmphu 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
typesense/typesense:0.23.03accb727cbe2
perl@5.22.1-9ubuntu0.9
5.22.1-9ubuntu0.9+esm3

Open the chart page →

3,876
infrahub-enterpriseinfrahub-enterpriseVerified publisher4.19.24 of 5See more

infrahub-enterprise infrahub-enterprise 4.19.2

4 of the 5 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
perl@5.36.0-7+deb12u2
no fix listed
library/neo4j:2026.05.0-enterprise2caf944aa4a5
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,625
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
instill/artifact-backend:b28766ac4a393e601ed
perl@5.40.1-6
5.40.1-6+deb13u1
instill/mgmt-backend:d0933d4ebe12f77a3f9
perl@5.40.1-6
5.40.1-6+deb13u1
instill/model-backend:611f0f2e980125e5ba5
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

31,122
dayz-dedicated-serverjespernohrVerified publisher0.1.21 of 3See more

dayz-dedicated-server jespernohr 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,363
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

4,526
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

7,378
webdavk8s-webdavVerified publisher0.0.71 of 1See more

webdav k8s-webdav 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/httpd:2.4979c38c2228d
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,703
kiali-operatorkiali2.32.01 of 1See more

kiali-operator kiali 2.32.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
perl@0:5.74-481.1.el9_6
0:5.74-484.el9_8

Open the chart page →

1,085
klancesklances0.1.41 of 1See more

klances klances 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,715
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:6143f7bfc2358
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,303
radondb-mysqlkubesphere-testVerified publisher1.0.11 of 3See more

radondb-mysql kubesphere-test 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

7,384
kubevpnkubevpn-charts2.11.71 of 1See more

kubevpn kubevpn-charts 2.11.7

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/kubenetworks/kubevpn:v2.11.7cce8ff866f60
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,626
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.01 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
dongjiang1989/lxcfs:v6.0.34bf9ae391948
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3

Open the chart page →

11,675
lightsteplightstepsatellite1.2.41 of 1See more

lightstep lightstepsatellite 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm3

Open the chart page →

15,340
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

7,944
mariadbmariadbVerified publisher0.4.01 of 1See more

mariadb mariadb 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8

Open the chart page →

2,458
kubecostmesosphere-stable0.37.52 of 9See more

kubecost mesosphere-stable 0.37.5

2 of the 9 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.30.5744f84cf7493
perl@5.36.0-7+deb12u1
no fix listed
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.8

Open the chart page →

17,799
mogenius-operatormogeniusOfficialVerified publisher2.29.01 of 2See more

mogenius-operator mogenius 2.29.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
valkey/valkey:9.1.164e361b630ec
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

956
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.042a8200d3597
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

4,077
observalobservalVerified publisher1.13.13 of 8See more

observal observal 1.13.1

3 of the 8 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3810861a2e2d0
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
library/postgres:16f1c3376c26f2
perl@5.40.1-6
5.40.1-6+deb13u1
ghcr.io/observal/observal-api:1.13.1153b8b893232
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,916
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,244
oesopsmxVerified publisher4.0.327 of 25See more

oes opsmx 4.0.32

7 of the 25 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
perl@5.22.1-9ubuntu0.9
5.22.1-9ubuntu0.9+esm3
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
perl@0:5.74-473.module+el8.10.0+21354+3ad137bb
0:5.74-475.module+el8.10.0+24767+f69b15b5
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
perl@0:5.74-473.module+el8.10.0+21354+3ad137bb
0:5.74-475.module+el8.10.0+24767+f69b15b5
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
perl@5.40.1-6
5.40.1-6+deb13u1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
perl@0:1.28-419.el8_4.1
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.28-423.el8_10.1
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
perl@0:5.74-473.module+el8.10.0+21354+3ad137bb
0:5.74-475.module+el8.10.0+24767+f69b15b5

Open the chart page →

108,315
part-dbpart-dbVerified publisher0.1.21 of 1See more

part-db part-db 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
jbtronics/part-db1:latest5db71f6db59d
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,344
redispascaliskeVerified publisher2.1.01 of 1See more

redis pascaliske 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/redis:8.0.3be0a135f1955
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,869
phpmyadminphpmyadminVerified publisher1.0.31 of 1See more

phpmyadmin phpmyadmin 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,650
prometheus-prefect-exporterprefectVerified publisher2026.8.71410241 of 1See more

prometheus-prefect-exporter prefect 2026.8.7141024

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
prefecthq/prometheus-prefect-exporter:4.0.050d527a190ae
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,022
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/nginx:1.27.409369da6b103
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,465
repoflowrepoflow-helm-public0.9.13 of 8See more

repoflow repoflow-helm-public 0.9.1

3 of the 8 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
library/elasticsearch:8.15.0310b9fc03b06
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm3
library/postgres:16.24aea012537ed
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

13,647
nominatimrobjuz6.4.12 of 4See more

nominatim robjuz 6.4.1

2 of the 4 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
perl@5.36.0-7+deb12u1
no fix listed
mediagis/nominatim:5.3.27923a8e67197
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

8,783
rocketmq-clusterrocketmq12.6.01 of 2See more

rocketmq-cluster rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

6,400
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3

Open the chart page →

24,566
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8

Open the chart page →

3,469
lldapself-hosters-by-nightVerified publisher0.5.21 of 2See more

lldap self-hosters-by-night 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,423
skypilotskypilotOfficialVerified publisher0.13.01 of 3See more

skypilot skypilot 0.13.0

1 of the 3 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,926
kafka-chartsoldevelo-kafka-chart32.4.41 of 1See more

kafka-chart soldevelo-kafka-chart 32.4.4

1 of the 1 container images this version deploys carry CVE-2026-13221.

Container imageDigestPackageFixed in
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,377

Container images carrying it

2,391 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/wittdennis/homeassistant-otbr:4.2.31b53b0b3488e
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
perl@5.36.0-7
no fix listed
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm3
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/wrenix/autopush-rs/autoconnect:1.84.285f93ced88b2
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/wrenix/autopush-rs/autoendpoint:1.84.2d95e9a124eed
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/yourls/yourls:1.10.69b220ea83329
perl@5.40.1-6
5.40.1-6+deb13u1
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.1da0b5eb7721a
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.8
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm3
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm3
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.8
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm3
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
perl@5.36.0-7+deb12u3
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest5d55a742a2bc
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:latest8be3ed26f746
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/aktosecurity/akto-threat-detection:latest3f103ce347ce
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.3
1
public.ecr.aws/aktosecurity/redis47200b041382
perl@5.36.0-7+deb12u3
no fix listed
1
public.ecr.aws/aktosecurity/redis:latestV8.6.2832d7785830f
perl@5.40.1-6
5.40.1-6+deb13u1
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/datadog/cloudprem:v0.1.33bda08753668d
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
perl@5.40.1-6
5.40.1-6+deb13u1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
perl@5.36.0-7+deb12u1
no fix listed
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.8
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
perl@5.40.1-6+e4
5.40.1-6+e15
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
perl@5.36.0-7+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
perl@5.36.0-7+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
perl@5.36.0-7+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
perl@5.36.0-7+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
perl@5.36.0-7
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
perl@5.36.0-7+deb12u3
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.