CVE-2026-42497
HighAdvisory
Published 26 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.004
- 35th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,329
- of 17,790 indexed, latest versions
- Container images
- 2,300
- deployed by those charts
- Fix available
- 1 of 1
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 2,329 of 17,790 indexed charts deploy, on 2,300 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| perldeb | 5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+43 more | 5.38.2-3.2ubuntu0.3, 5.40.1-6+deb13u1, 5.40.1-6+e6 | 2,300 |
Charts affected
2,329 by stars
Container images carrying it
2,300 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 2b6db27eaf3d | perl | no fix listed | 3 |
| quay.io/ | 5bf041aacadd | perl | 5.38.2-3.2ubuntu0.3 | 3 |
| quay.io/ | 60566529446a | perl | 5.38.2-3.2ubuntu0.3 | 3 |
| quay.io/ | 721b5c9634d4 | perl | 5.38.2-3.2ubuntu0.3 | 3 |
| quay.io/ | 39f2c6e0af38 | perl | no fix listed | 3 |
| quay.io/ | 01d5d8c4cecb | perl | 5.38.2-3.2ubuntu0.3 | 3 |
| quay.io/ | 4c3b91bebd3d | perl | no fix listed | 3 |
| quay.io/ | f296c2ec5db7 | perl | no fix listed | 3 |
| quay.io/ | 9d25865295af | perl | 5.38.2-3.2ubuntu0.3 | 3 |
| quay.io/ | ea6dd1e4ce71 | perl | 5.38.2-3.2ubuntu0.3 | 3 |
| quay.io/ | 709c7da19c5a | perl | no fix listed | 3 |
| actualbudget/ | 552beab3dec8 | perl | no fix listed | 2 |
| alazidis/ | 0e8c84152201 | perl | 5.38.2-3.2ubuntu0.3 | 2 |
| apache/ | 7cdfd8deec92 | perl | no fix listed | 2 |
| apache/ | 319cd8a81ed1 | perl | 5.38.2-3.2ubuntu0.3 | 2 |
| apache/ | ae0b86d3c4d0 | perl | 5.38.2-3.2ubuntu0.3 | 2 |
| bitnamilegacy/ | 00176a47afa0 | perl | no fix listed | 2 |
| bitnamilegacy/ | 99b408c15272 | perl | no fix listed | 2 |
| bitnamilegacy/ | 33ce23601fc9 | perl | no fix listed | 2 |
| bitnamilegacy/ | d3bf3910f148 | perl | no fix listed | 2 |
| bitnamilegacy/ | 94bc968141e7 | perl | no fix listed | 2 |
| bitnamilegacy/ | f12387ec882b | perl | no fix listed | 2 |
| bitnamilegacy/ | 5927ff3702df | perl | no fix listed | 2 |
| bitnamilegacy/ | 32869e769b7e | perl | no fix listed | 2 |
| bitnami/ | ab4d5b45116e | perl | 5.40.1-6+deb13u1 | 2 |
| blockstack/ | f79944317326 | perl | no fix listed | 2 |
| cagriekin/ | 99e17aa165df | perl | 5.40.1-6+deb13u1 | 2 |
| cfssl/ | c9018c2ddf0b | perl | no fix listed | 2 |
| chromedp/ | 313ed7255ae1 | perl | 5.40.1-6+deb13u1 | 2 |
| clickhouse/ | ed9640bfff07 | perl | no fix listed | 2 |
| dagster/ | 5947f9ae481c | perl | 5.40.1-6+deb13u1 | 2 |
| datagrok/ | f5876d3aebb8 | perl | no fix listed | 2 |
| eqalpha/ | 6537505c4235 | perl | no fix listed | 2 |
| eqalpha/ | eceb1806730c | perl | no fix listed | 2 |
| fireflyiii/ | fe4ecec4c2ba | perl | 5.40.1-6+deb13u1 | 2 |
| fireflyiii/ | ab52bf932546 | perl | 5.40.1-6+deb13u1 | 2 |
| freeradius/ | 21c8bfa904d8 | perl | no fix listed | 2 |
| geoservercloud/ | 756559ee788a | perl | no fix listed | 2 |
| geoservercloud/ | 99540eef78ad | perl | no fix listed | 2 |
| geoservercloud/ | 5c254c53a357 | perl | no fix listed | 2 |
| geoservercloud/ | c687b1cbc891 | perl | no fix listed | 2 |
| geoservercloud/ | 5288f320cf36 | perl | no fix listed | 2 |
| geoservercloud/ | a30a60ac6cd0 | perl | no fix listed | 2 |
| gjeanmart/ | 926264c8f2d1 | perl | no fix listed | 2 |
| gotenberg/ | 87c16b9f3642 | perl | 5.40.1-6+deb13u1 | 2 |
| gotenberg/ | f29984bd1e22 | perl | 5.40.1-6+deb13u1 | 2 |
| gotson/ | 6c2a967bbe9a | perl | no fix listed | 2 |
| gradiant/ | 015b30d5fa0f | perl | no fix listed | 2 |
| grafana/ | 7790f6f7fbd8 | perl | 5.38.2-3.2ubuntu0.3 | 2 |
| grafana/ | f94b1c82957a | perl | 5.38.2-3.2ubuntu0.3 | 2 |