StackRadar

CVE-2026-19487

Medium

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,505
of 17,828 indexed, latest versions
Container images
2,511
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,505 of 17,828 indexed charts deploy, on 2,511 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+44 more5.18.2-2ubuntu1.7+esm9, 5.22.1-9ubuntu0.9+esm4, 5.26.1-6ubuntu0.7+esm4, 5.30.0-9ubuntu0.5+esm4+4 more2,511
OSV records
DEBIAN-CVE-2026-19487UBUNTU-CVE-2026-19487ECHO-f6c7-844b-6a34
Also known as
USN-8736-1, USN-8736-2

Charts affected

2,505 by stars
ChartLatestAffected imagesRadar Score
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,709
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,701
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
perl@5.40.1-6+deb13u1
no fix listed

Open the chart page →

1,589
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
yandex/clickhouse-server:21.3.204eccfffb01d7
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4

Open the chart page →

9,340
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.9

Open the chart page →

8,105

Container images carrying it

2,511 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/linuxserver/calibre-web:latest0767226fcf20
perl@5.38.2-3.2ubuntu0.4
5.38.2-3.2ubuntu0.6
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.6
1
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/duplicati:lateste1fdac6133ad
perl@5.38.2-3.2ubuntu0.4
5.38.2-3.2ubuntu0.6
1
ghcr.io/linuxserver/hedgedoc:version-1.9.0792a12ee976a
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/mariadb:version-110.4.21mariabionic7a94d7e89f52
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/ombi:4.53.50caadf03b804
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
1
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.9
1
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.6
1
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
1
ghcr.io/litesql/ha:latest7376ffffc1a2
perl@5.40.1-6
no fix listed
1
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
perl@5.40.1-6
no fix listed
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
perl@5.40.1-6
no fix listed
1
ghcr.io/lloesche/valheim-server:latestc885aa902faf
perl@5.40.1-6+deb13u1
no fix listed
1
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.9
1
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.9
1
ghcr.io/loxilb-io/loxilb:latesta475b43946b3
perl@5.34.0-3ubuntu1.8
5.34.0-3ubuntu1.9
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.6
1
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
perl@5.40.1-6
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/mcp-hangar/mcp-hangar:2.21.2cbddeed1a9f0
perl@5.40.1-6
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
perl@5.40.1-6
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
perl@5.40.1-6
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
perl@5.40.1-6
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
perl@5.40.1-6
no fix listed
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
perl@5.40.1-6
no fix listed
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.6
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.6
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.6
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.6
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.6
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
perl@5.40.1-6
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.6
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
1
ghcr.io/mitos-run/mitos-forkd:v1.6.0979b462ab7d6
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.9
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
perl@5.40.1-6
no fix listed
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
perl@5.36.0-7
no fix listed
1
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
perl@5.40.1-6
no fix listed
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.9
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
perl@5.40.1-6
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.