StackRadar

CVE-2026-42496

Critical

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,174
of 17,792 indexed, latest versions
Container images
2,117
deployed by those charts
Fix available
2 of 2
affected packages

Important: perl-Archive-Tar security update

Carried by container images the latest versions of 2,174 of 17,792 indexed charts deploy, on 2,117 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+30 more5.18.2-2ubuntu1.7+esm7, 5.26.1-6ubuntu0.7+esm2, 5.30.0-9ubuntu0.5+esm2, 5.34.0-3ubuntu1.7+5 more2,115
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.12
OSV records
DEBIAN-CVE-2026-42496UBUNTU-CVE-2026-42496RLSA-2026:30856ECHO-1732-bcf6-7970
Also known as
USN-8467-1

Charts affected

2,174 by stars
ChartLatestAffected imagesRadar Score
dv-podcharonOfficialVerified publisher0.19.12 of 5See more

dv-pod charon 0.19.1

2 of the 5 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
obolnetwork/charon:v1.10.0278c7e2897b6
perl@5.40.1-6
5.40.1-6+deb13u1
sigp/lighthouse:v8.1.344aa773dcf27
perl@5.34.0-3ubuntu1.5
5.34.0-3ubuntu1.7

Open the chart page →

7,530
helioscharonVerified publisher0.1.51 of 1See more

helios charon 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
obolnetwork/helios:e10e753cb7e97d39d46
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.3

Open the chart page →

2,140
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,873
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,837
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,951
home-assistant-otbrcharts-derwitt-devVerified publisher2.1.41 of 1See more

home-assistant-otbr charts-derwitt-dev 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/homeassistant-otbr:4.2.5282f840612d9
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,316
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
perl@5.26.1-6ubuntu0.7
5.26.1-6ubuntu0.7+esm2

Open the chart page →

12,887
paperless-ngxcharts-derwitt-devVerified publisher2.1.41 of 1See more

paperless-ngx charts-derwitt-dev 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,664
chat-searchchat-searchVerified publisher0.1.71 of 1See more

chat-search chat-search 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/hemslo/chat-search:latest39d48995a5bd
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,068
opensipschetan-opensips0.1.01 of 1See more

opensips chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
chetangautamm/repo:Opensips_Buildb4b94155ff5a
perl@5.18.2-2ubuntu1.7
5.18.2-2ubuntu1.7+esm7

Open the chart page →

30,226
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm2

Open the chart page →

12,608
mysqld-exporterchoerodon0.1.01 of 1See more

mysqld-exporter choerodon 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,861
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,976
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

5,996
proxysqlchristianhuthVerified publisher3.1.11 of 1See more

proxysql christianhuth 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
proxysql/proxysql:3.0.110e95d1b7cc32
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,294
timetaggerchristianhuthVerified publisher2.2.01 of 1See more

timetagger christianhuth 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,983
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,125
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.7

Open the chart page →

4,884
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.7

Open the chart page →

6,559
tor-proxychronicleVerified publisher0.1.01 of 1See more

tor-proxy chronicle 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
btcpayserver/tor:0.4.8.10e9585b68dc6b
perl@5.36.0-7
no fix listed

Open the chart page →

3,358
zksyncchronicleVerified publisher0.1.02 of 2See more

zksync chronicle 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
perl@5.40.1-6
5.40.1-6+deb13u1
matterlabs/external-node:v24.0.06cbfea4c694a
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

6,052
kamaji-etcdclastixVerified publisher0.17.01 of 4See more

kamaji-etcd clastix 0.17.0

1 of the 4 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

12,075
helmchartclouddrove1.4.01 of 1See more

helmchart clouddrove 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,861
kube-acp-stackcloudentity2.28.02 of 7See more

kube-acp-stack cloudentity 2.28.0

2 of the 7 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
perl@5.36.0-7+deb12u2
no fix listed
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.7

Open the chart page →

21,064
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm2

Open the chart page →

29,980
guestbookcloudnativeapp0.2.01 of 3See more

guestbook cloudnativeapp 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
resouer/redis-slave:v2e2f198b49ba7
perl@5.18.2-2ubuntu1
5.18.2-2ubuntu1.7+esm7

Open the chart page →

36,934
postgresqlcloudnativeapp5.0.01 of 2See more

postgresql cloudnativeapp 5.0.0

1 of the 2 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
bitnami/minideb:latestab4d5b45116e
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

836
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

23,721
seleniumcloudnativeapp1.0.81 of 1See more

selenium cloudnativeapp 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm2

Open the chart page →

11,848
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
robotshop/rs-mongodb:latest119b545823cd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm2

Open the chart page →

29,646
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad2 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

2 of the 6 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
perl@5.36.0-7+deb12u1
no fix listed
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.7

Open the chart page →

18,400
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm2

Open the chart page →

12,521
cloudlaunch-servercloudve0.2.02 of 5See more

cloudlaunch-server cloudve 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
bitnami/minideb:latestab4d5b45116e
perl@5.40.1-6
5.40.1-6+deb13u1
cloudve/cloudlaunch-server:latest4a3d7fae90bb
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm2

Open the chart page →

12,224
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm2

Open the chart page →

11,656
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,610
galaxy-depscloudve1.1.11 of 7See more

galaxy-deps cloudve 1.1.1

1 of the 7 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

10,599
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm2

Open the chart page →

16,155
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
perl@5.18.2-2ubuntu1.4
5.18.2-2ubuntu1.7+esm7
galaxy/galaxy-stable:v18.018e577a626dfd
perl@5.18.2-2ubuntu1.4
5.18.2-2ubuntu1.7+esm7

Open the chart page →

70,987
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
cloudve/janis-terminal:latestaf56e77ca587
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm2

Open the chart page →

14,372
postgresqlcloudve4.0.01 of 2See more

postgresql cloudve 4.0.0

1 of the 2 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
bitnami/minideb:latest835e5f8392c3
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

836
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

6,181
terminalmancloudve0.3.41 of 1See more

terminalman cloudve 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
cloudve/ttyd:latestd79c1c5881c0
perl@5.26.1-6ubuntu0.3
5.26.1-6ubuntu0.7+esm2

Open the chart page →

13,187
authentikcluster-deploy0.2.01 of 1See more

authentik cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,527
chowdacluster-deploy0.2.01 of 1See more

chowda cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,856
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
perl@5.36.0-7
no fix listed

Open the chart page →

8,093
pbcore-utilcluster-deploy0.0.11 of 1See more

pbcore-util cluster-deploy 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,214
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

7,191
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

6,980
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,950
web-chartcms-ktcloudlab0.1.01 of 1See more

web-chart cms-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42496.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,861

Container images carrying it

2,117 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
perl@5.36.0-7+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
perl@5.30.0-9ubuntu0.2
5.30.0-9ubuntu0.5+esm2
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
perl@5.36.0-7
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
perl@5.36.0-7+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
perl@5.36.0-7+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.