StackRadar

CVE-2026-19487

Medium

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,459
of 17,821 indexed, latest versions
Container images
2,450
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,459 of 17,821 indexed charts deploy, on 2,450 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+44 more5.18.2-2ubuntu1.7+esm9, 5.22.1-9ubuntu0.9+esm4, 5.26.1-6ubuntu0.7+esm4, 5.30.0-9ubuntu0.5+esm4+4 more2,450
OSV records
DEBIAN-CVE-2026-19487UBUNTU-CVE-2026-19487ECHO-f6c7-844b-6a34
Also known as
USN-8736-1, USN-8736-2

Charts affected

2,459 by stars
ChartLatestAffected imagesRadar Score
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,196
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,956
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
perl@5.40.1-6
no fix listed

Open the chart page →

1,338
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
no fix listed

Open the chart page →

1,956
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,718
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,697
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
perl@5.40.1-6+deb13u1
no fix listed

Open the chart page →

1,956
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
yandex/clickhouse-server:21.3.204eccfffb01d7
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.9

Open the chart page →

7,966

Container images carrying it

2,450 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.4-thick3c20900b5381
perl@5.40.1-6
no fix listed
1
ghcr.io/kamu-data/kamu-api-server:0.90.0e61435d44913
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/klicktipp/csa-exporter:0.3.12c69513f9d85
perl@5.40.1-6
no fix listed
1
ghcr.io/klicktipp/snds-exporter:v0.2.4a23b389cb3c5
perl@5.40.1-6
no fix listed
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
perl@5.26.1-6ubuntu0.6
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/kubelauncher/cassandrab66aba320083
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/etcd8ab954711fb9
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/keycloakafe3bd73d7cf
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/kubectl7280594a2f18
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/mariadbe25056a6ec52
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/memcachedb599ca6b3ff3
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/mongodb9bc37ed78a8b
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/mysqle9609bd50416
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/openldap8978aa002bc0
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
1
ghcr.io/kubelauncher/postgresql1a27e11e5925
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/rabbitmqff5a36a457f1
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.6
1
ghcr.io/kubelauncher/redisbcd8e9a6224f
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubelauncher/zookeeper7826e9caa461
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/kubenetworks/kubevpn:v2.11.93feb9da85270
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
perl@5.40.1-6
no fix listed
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
perl@5.40.1-6
no fix listed
1
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
perl@5.36.0-7
no fix listed
1
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.6
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/linuxserver/booksonic:version-1.2677efca1065d
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
perl@5.38.2-3.2ubuntu0.4
5.38.2-3.2ubuntu0.6
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.6
1
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/hedgedoc:version-1.9.0792a12ee976a
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/mariadb:version-110.4.21mariabionic7a94d7e89f52
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/ombi:4.53.50caadf03b804
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.