StackRadar

CVE-2026-19487

Medium

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,505
of 17,828 indexed, latest versions
Container images
2,511
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,505 of 17,828 indexed charts deploy, on 2,511 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+44 more5.18.2-2ubuntu1.7+esm9, 5.22.1-9ubuntu0.9+esm4, 5.26.1-6ubuntu0.7+esm4, 5.30.0-9ubuntu0.5+esm4+4 more2,511
OSV records
DEBIAN-CVE-2026-19487UBUNTU-CVE-2026-19487ECHO-f6c7-844b-6a34
Also known as
USN-8736-1, USN-8736-2

Charts affected

2,505 by stars
ChartLatestAffected imagesRadar Score
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,709
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,701
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
perl@5.40.1-6+deb13u1
no fix listed

Open the chart page →

1,589
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
yandex/clickhouse-server:21.3.204eccfffb01d7
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4

Open the chart page →

9,340
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.9

Open the chart page →

8,105

Container images carrying it

2,511 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/airflow:2.8.4-python3.964e58748b6b9
perl@5.36.0-7+deb12u1
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
perl@5.36.0-7+deb12u1
no fix listed
1
apache/airflow:2.8.1e5560ad0b86e
perl@5.36.0-7+deb12u1
no fix listed
1
apache/apisix:3.16.0-ubuntu5e47692cac00
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
1
apache/camel-k:2.11.0d173e7efe258
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.9
1
apache/hertzbeat:1.8.075d48a62748f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
1
apache/iotdb:0.13.3-nodeafa47bf1692a
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
apache/nifi-registry:1.27.063b8e3e40742
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.9
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.9
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
apachepulsar/pulsar:3.0.79c9947de139d
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.9
1
apachepulsar/pulsar:2.9.0d056c89b7131
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
apachepulsar/pulsar:2.8.2d538416d5afe
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
apache/ranger:2.7.076c176e8a0e4
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.9
1
apache/rocketmq:5.3.0434d8398f996
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.6
1
apache/rocketmq-exporter:0.0.2c8fb51195444
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.9
1
apache/skywalking-oap-server:9.2.0133d35d2c263
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.9
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
apache/skywalking-ui:9.2.0295f1dc87d98
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.9
1
apache/skywalking-ui:8.9.180530f0308a5
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
apache/superset:4.0.1ab9467fd712c
perl@5.36.0-7+deb12u1
no fix listed
1
apache/tika:latest-full80072bb73dd3
perl@5.40.1-7ubuntu0.1
5.40.1-7ubuntu0.2
1
apache/tika:3.3.1.090b7fa1dc018
perl@5.40.1-7build1
5.40.1-7ubuntu0.2
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
perl@5.40.1-6
no fix listed
1
appwrite/new:1.1.96-self-hostedaf65a77db50e
perl@5.40.1-6
no fix listed
1
arbuzov/claude-code-api:0.1.02d7dd8070610
perl@5.36.0-7+deb12u2
no fix listed
1
archivebox/archivebox:0.7.41a5a37331091
perl@5.36.0-7+deb12u3
no fix listed
1
arilot/docker-bitcoind:0.17.127a4f7e0f9f1
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm4
1
aristidetm/basic-notebook:3.6.5469dbc951224
perl@5.36.0-7+deb12u1
no fix listed
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
perl@5.36.0-7+deb12u1
no fix listed
1
artifacthub/tracker:v1.23.05368d21a6e5c
perl@5.40.1-6
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
perl@5.36.0-7+deb12u1
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
perl@5.30.0-9ubuntu0.4
5.30.0-9ubuntu0.5+esm4
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
assistiot/identity-manager_db:latest0d3e6d35f168
perl@5.36.0-7
no fix listed
1
assistiot/location_processing:lateste9bae124095f
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.9
1
assistiot/open_api_backend:1.1.230812ba93555
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.9
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
perl@5.36.0-7+deb12u1
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
perl@5.36.0-7+deb12u1
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
perl@5.36.0-7
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
perl@5.30.0-9ubuntu0.3
5.30.0-9ubuntu0.5+esm4
1
athou/commafeed:6.2.0-postgresql5e388351df1a
perl@5.40.1-6
no fix listed
1
atlassian/bamboo:12.1.114af4bb6c8d46
perl@5.38.2-3.2ubuntu0.4
5.38.2-3.2ubuntu0.6
1
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
perl@5.38.2-3.2ubuntu0.4
5.38.2-3.2ubuntu0.6
1
atlassian/bitbucket:10.2.705933f2b1cfd
perl@5.38.2-3.2ubuntu0.4
5.38.2-3.2ubuntu0.6
1
atlassian/confluence-server:7.10.03b9222ab32ef
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.9
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.