StackRadar

CVE-2026-19487

Medium

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,505
of 17,828 indexed, latest versions
Container images
2,511
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,505 of 17,828 indexed charts deploy, on 2,511 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+44 more5.18.2-2ubuntu1.7+esm9, 5.22.1-9ubuntu0.9+esm4, 5.26.1-6ubuntu0.7+esm4, 5.30.0-9ubuntu0.5+esm4+4 more2,511
OSV records
DEBIAN-CVE-2026-19487UBUNTU-CVE-2026-19487ECHO-f6c7-844b-6a34
Also known as
USN-8736-1, USN-8736-2

Charts affected

2,505 by stars
ChartLatestAffected imagesRadar Score
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,709
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,701
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
perl@5.40.1-6+deb13u1
no fix listed

Open the chart page →

1,589
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
perl@5.26.1-6ubuntu0.5
5.26.1-6ubuntu0.7+esm4
yandex/clickhouse-server:21.3.204eccfffb01d7
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4

Open the chart page →

9,340
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-19487.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
perl@5.34.0-3ubuntu1.7
5.34.0-3ubuntu1.9

Open the chart page →

8,105

Container images carrying it

2,511 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
80
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm4
80
library/nginx:1.31:latest:trixieabe47724e466
perl@5.40.1-6+deb13u1
no fix listed
63
library/nginx:1.31:1.31.5:latest:trixie05b8cb60c354
perl@5.40.1-6
no fix listed
42
library/postgres:18:18.6:18.6-trixie:latest4ef4dbc939d6
perl@5.40.1-6
no fix listed
39
library/postgres:18:18.6:18.6-trixie:latest86c951e05bf5
perl@5.40.1-6+deb13u1
no fix listed
29
library/redis:8.10.1:latest298e5b3bc566
perl@5.40.1-6
no fix listed
24
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
perl@5.40.1-6
no fix listed
17
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
perl@5.26.1-6ubuntu0.6
5.26.1-6ubuntu0.7+esm4
13
library/nginx:stabled5792f71a949
perl@5.40.1-6
no fix listed
13
library/redis:8.10.1:latest8a1efc5f4795
perl@5.40.1-6+deb13u1
no fix listed
12
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
no fix listed
11
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
5.22.1-9ubuntu0.9+esm4
11
library/mongo:5.0.6-focal8e70544b6c76
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
10
library/nginx:stable0aa2d81d65bc
perl@5.40.1-6+deb13u1
no fix listed
10
library/rabbitmq:3.9-management8a279e9396a8
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.9
10
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.9
8
library/mongo:8:8.3.8:latest5211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.6
8
library/postgres:16a3b7f434b2dc
perl@5.40.1-6+deb13u1
no fix listed
8
library/rabbitmq:3.13-management:3-managemente582c0bc7766
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.6
8
valkey/valkey:9.1.2:latestc123e3715db6
perl@5.40.1-6
no fix listed
8
library/postgres:17f4c66b820c6f
perl@5.40.1-6+deb13u1
no fix listed
7
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
perl@5.36.0-7+deb12u2
no fix listed
6
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
perl@5.36.0-7+deb12u2
no fix listed
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
perl@5.36.0-7+deb12u2
no fix listed
6
jellyfin/jellyfin:10.11:10.11.11:latestaefb67e6a7ff
perl@5.40.1-6
no fix listed
6
library/kong:3.912972ce1ab63
perl@5.38.2-3.2ubuntu0.4
5.38.2-3.2ubuntu0.6
6
library/mariadb:12.3.3:latest:ltsdd9b303aed4f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.6
6
library/postgres:18.4a02db8cac496
perl@5.40.1-6
no fix listed
6
oomk8s/readiness-check:2.0.07daa08b81954
perl@5.22.1-9ubuntu0.2
5.22.1-9ubuntu0.9+esm4
6
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
perl@5.36.0-7+deb12u3
no fix listed
6
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
perl@5.40.1-6
no fix listed
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
no fix listed
6
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
no fix listed
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
perl@5.36.0-7+deb12u1
no fix listed
5
flaresolverr/flaresolverr:latest:v3.5.0139dfee1c6f8
perl@5.36.0-7+deb12u3
no fix listed
5
library/httpd:2.4:2.4.68:latest454942557d44
perl@5.40.1-6+deb13u1
no fix listed
5
library/mongo:4.44be76f674fc4
perl@5.30.0-9ubuntu0.5
5.30.0-9ubuntu0.5+esm4
5
library/mongo:8:8.3.11:latest5d7043a4ffe0
perl@5.38.2-3.2ubuntu0.4
5.38.2-3.2ubuntu0.6
5
library/phpmyadmin:5.2.3-apache:latest9e915766488a
perl@5.40.1-6+deb13u1
no fix listed
5
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
no fix listed
5
library/postgres:14816cf7d06ec3
perl@5.40.1-6+deb13u1
no fix listed
5
library/postgres:15dfbbb0ad8cab
perl@5.40.1-6+deb13u1
no fix listed
5
library/redis:7.2:7.2-bookworm0637954999d0
perl@5.36.0-7+deb12u3
no fix listed
5
library/redis:6:6.2e7b96daa9a18
perl@5.36.0-7+deb12u3
no fix listed
5
solsson/kafka:latest41e5d8f6f290
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm4
5
valkey/valkey:9.1.1:9.1.1-trixie64e361b630ec
perl@5.40.1-6
no fix listed
5
vaultwarden/server:1.37.2:latest094b5689ed81
perl@5.40.1-6
no fix listed
5
artifacthub/postgres:latest4fd34fa635cc
perl@5.40.1-6
no fix listed
4
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
perl@5.36.0-7+deb12u2
no fix listed
4

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.