StackRadar

CVE-2026-19487

Medium

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,501
of 17,821 indexed, latest versions
Container images
2,506
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,501 of 17,821 indexed charts deploy, on 2,506 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+44 more5.18.2-2ubuntu1.7+esm9, 5.22.1-9ubuntu0.9+esm4, 5.26.1-6ubuntu0.7+esm4, 5.30.0-9ubuntu0.5+esm4+4 more2,506
OSV records
DEBIAN-CVE-2026-19487UBUNTU-CVE-2026-19487ECHO-f6c7-844b-6a34
Also known as
USN-8736-1, USN-8736-2

Charts affected

2,501 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.9

Open the chart page →

7,966

Container images carrying it

2,506 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pk910/powfaucet:v2-stable3dcae6a62896
perl@5.36.0-7+deb12u2
no fix listed
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
perl@5.38.2-3.2ubuntu0.4
5.38.2-3.2ubuntu0.6
1
platform9community/admin-server:latestde3fa9b70df1
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
platform9community/api-gateway:latest40a4970de568
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
platform9community/customers-service:latest2089811e5cc6
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
platform9community/vets-service:latestd1165c94dfb3
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
platform9community/visits-service:latest8d11b50368c6
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
plexinc/pms-docker:1.43.3.10896-cb3ebc72d83a425ae9e13
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.6
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
perl@5.22.1-9ubuntu0.5
5.22.1-9ubuntu0.9+esm4
1
pockost/matomo:5.13.07f5d293cbe4e
perl@5.40.1-6
no fix listed
1
pococze/python-hello-elos:2.0.07a1aab425e51
perl@5.36.0-7+deb12u1
no fix listed
1
polyaxon/polyaxon-api:2.17.0163707082036
perl@5.40.1-6+deb13u1
no fix listed
1
polyaxon/polyaxon-streams:2.17.0a5fec70e757b
perl@5.40.1-6+deb13u1
no fix listed
1
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
perl@5.38.2-3.2ubuntu0.4
5.38.2-3.2ubuntu0.6
1
postgis/postgis:18-3.67e00e8c3539f
perl@5.40.1-6
no fix listed
1
powerdns/pdns-recursor-54:5.4.533aadc74a8d6
perl@5.40.1-6
no fix listed
1
pozetroninc/keydb:v6.0.1653ae64f29da8
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm4
1
pposkrobko/risk-advisor:v1.0.0eaf260341dba
perl@5.22.1-9
5.22.1-9ubuntu0.9+esm4
1
praravind1801/helmimages:3.0.0f29d637b9ce1
perl@5.36.0-7+deb12u1
no fix listed
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
perl@5.36.0-7+deb12u1
no fix listed
1
prefecthq/prefect:3.8.6-python3.11f518ebb9c353
perl@5.40.1-6+deb13u1
no fix listed
1
prefecthq/prometheus-prefect-exporter:4.1.06e0e79cabdc2
perl@5.40.1-6
no fix listed
1
pretix/standalone:2026.7.05df3b7aa852e
perl@5.40.1-6
no fix listed
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
perl@5.40.1-6
no fix listed
1
project2team4/react:latest3ff031a08887
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.6
1
promzeus/redis-sentinel-gateway:v182f6d56e280b
perl@5.36.0-7+deb12u1
no fix listed
1
prowlercloud/prowler-api:5.31.14f252d579be2
perl@5.36.0-7+deb12u3
no fix listed
1
proxysql/proxysql:3.0.8947a7abad45b
perl@5.40.1-6
no fix listed
1
proxysql/proxysql:2.7.3a4d6c35c2949
perl@5.36.0-7+deb12u1
no fix listed
1
pschichtel/mindustry-server:v145.1b543e9c2d371
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.9
1
psorab/elibrary:latest53b68896c4ce
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm4
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
puppet/puppet-agent:7.14.00b6fd9a6b7da
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
qdrant/qdrant:v1.7.45f2a56b95266
perl@5.36.0-7+deb12u1
no fix listed
1
qdrant/qdrant:v1.4.166ee661d5241
perl@5.36.0-7
no fix listed
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
perl@5.40.1-6
no fix listed
1
qonstrukt/php:8.4-v8-apache089af7925aa1
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.6
1
quickwit/quickwit:v0.8.1d29332bdadcc
perl@5.36.0-7+deb12u1
no fix listed
1
qumine/minecraft-server:v0.1.15c0b650d51132
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.9
1
qxip/qryn:3.2.3977acc9c7a9fd
perl@5.36.0-7+deb12u1
no fix listed
1
rabeh/apibootspring:1.0941007b6946e
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.9
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.6
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.6
1
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
perl@5.22.1-9ubuntu0.5
5.22.1-9ubuntu0.9+esm4
1
razorbladex401/dayz:latest6a4d79248e7d
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.9
1
readysettech/sqp:latest588f3507280e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
1
readysettech/sqp-duckdb:latest67a83203ce60
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.