StackRadar

CVE-2026-48961

High

Advisory

Published 27 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,175
of 17,797 indexed, latest versions
Container images
2,071
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,175 of 17,797 indexed charts deploy, on 2,071 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.40.1-6+deb13u1, 5.40.1-6+e92,071
OSV records
DEBIAN-CVE-2026-48961UBUNTU-CVE-2026-48961ECHO-3bd6-6520-0759

Charts affected

2,175 by stars
ChartLatestAffected imagesRadar Score
observoorethereum-helm-chartsVerified publisher0.0.31 of 1See more

observoor ethereum-helm-charts 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ethpandaops/observoor:masterc7e5055defcb
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,538
powfaucetethereum-helm-chartsVerified publisher1.2.11 of 1See more

powfaucet ethereum-helm-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
pk910/powfaucet:v2-stable3dcae6a62896
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

4,497
rpc-snooperethereum-helm-chartsVerified publisher0.0.21 of 1See more

rpc-snooper ethereum-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ethpandaops/rpc-snooper:latestc0b30fcf64bc
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,506
spamoorethereum-helm-chartsVerified publisher1.0.11 of 1See more

spamoor ethereum-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ethpandaops/spamoor:latest5f731b20ec50
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,145
web3signerethereum-helm-chartsVerified publisher1.0.61 of 4See more

web3signer ethereum-helm-charts 1.0.6

1 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
consensys/web3signer:latestf146a51a1ba3
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

2,052
beeethersphereVerified publisher0.17.41 of 1See more

bee ethersphere 0.17.4

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ethersphere/bee:2.2.0a884fd84b72f
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,490
beekeeperethersphereVerified publisher0.4.141 of 1See more

beekeeper ethersphere 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ethersphere/beekeeper:lateste4cda693ed63
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,634
bee-overlay-exporterethersphereVerified publisher0.1.01 of 1See more

bee-overlay-exporter ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/python:3.12-slim78387bc3881b
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

881
beeport-uiethersphereVerified publisher0.76.22 of 3See more

beeport-ui ethersphere 0.76.2

2 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1
library/node:ltsbe23f54a88d3
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,479
multichain-uiethersphereVerified publisher0.73.12 of 3See more

multichain-ui ethersphere 0.73.1

2 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1
library/node:ltsbe23f54a88d3
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,479
nethermindethersphereVerified publisher0.2.11 of 1See more

nethermind ethersphere 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
nethermind/nethermind:1.14.615517708c3b6
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

4,977
static-siteethersphereVerified publisher0.73.12 of 2See more

static-site ethersphere 0.73.1

2 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1
library/node:latestf5d1cc40abc1
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

7,077
network-toolseugen0.2.41 of 1See more

network-tools eugen 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/debian:bookworm6ebd97fa83de
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

993
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

20,955
evobotevobotVerified publisher0.1.11 of 1See more

evobot evobot 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,017
spring-boot-adminevryfs-ossVerified publisher0.1.101 of 1See more

spring-boot-admin evryfs-oss 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

6,049
extended-ceph-exporterextended-ceph-exporterVerified publisher1.10.01 of 2See more

extended-ceph-exporter extended-ceph-exporter 1.10.0

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
galexrt/extended-ceph-exporter:v1.8.05373078a3a08
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,962
capsizefairwinds-incubator0.2.01 of 1See more

capsize fairwinds-incubator 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/python:3-slimcad9a2c87176
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

836
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
perl@5.22.1-9ubuntu0.9
no fix listed

Open the chart page →

4,656
yelbfairwinds-incubator0.1.11 of 5See more

yelb fairwinds-incubator 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,132
event-generatorfalcosecurity0.4.01 of 1See more

event-generator falcosecurity 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
falcosecurity/event-generator:latest932956d86c99
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,813
jenkinsfatihtepe-jenkins1.0.01 of 1See more

jenkins fatihtepe-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,498
quickstartfeatureformVerified publisher0.1.12 of 3See more

quickstart featureform 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1
library/redis:latest298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,600
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
perl@5.34.0-3ubuntu1
no fix listed

Open the chart page →

13,512
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

6,157
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,531
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

14,714
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

10,816
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
perl@5.36.0-7
no fix listed
golenski/fibonacci-task-manager:2.0.03a2b36df247b
perl@5.36.0-7
no fix listed
golenski/fibonacci-worker:2.0.0954caf4aaf6a
perl@5.36.0-7
no fix listed

Open the chart page →

17,027
infrafibonacci-cluster-infraVerified publisher1.0.02 of 4See more

infra fibonacci-cluster-infra 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
perl@5.36.0-7+deb12u1
no fix listed
library/redis:7.4.1bb142a9c18ac
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

12,574
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

7,889
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,222
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
perl@5.40.1-6
5.40.1-6+deb13u1
fireflyiii/data-importer:version-2.2.3ab52bf932546
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,626
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,012
flask-contactsfirst-idror-chart1.0.12 of 3See more

flask-contacts first-idror-chart 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
perl@5.40.1-6
5.40.1-6+deb13u1
shashkist/flask-contacts-app:latest581de1fd6084
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,823
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
perl@5.30.0-9ubuntu0.5
no fix listed
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

65,325
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,878
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,520
apm-hubflanksourceVerified publisher0.0.472 of 2See more

apm-hub flanksource 0.0.47

2 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
perl@5.34.0-3ubuntu1.2
no fix listed
library/postgres:14156f0b253fd6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

6,175
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,682
flanksource-uiflanksourceVerified publisher1.4.3181 of 1See more

flanksource-ui flanksource 1.4.318

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.318891f21df54fb
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,588
mission-controlflanksourceVerified publisher0.1.3382 of 8See more

mission-control flanksource 0.1.338

2 of the 8 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
perl@5.36.0-7+deb12u3
no fix listed
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

8,956
mission-control-ai-assistantflanksourceVerified publisher1.0.121 of 1See more

mission-control-ai-assistant flanksource 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/flanksource/mission-control-ai-assistant:1.0.1229a635cbeeb5
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,322
flask-contactsflask-contacts-generic1.0.12 of 3See more

flask-contacts flask-contacts-generic 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
perl@5.40.1-6
5.40.1-6+deb13u1
shashkist/flask-contacts-app:latest581de1fd6084
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,823
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,097
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

5,703
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

8,057
fluentd-aggregatorfluentd-aggregatorOfficialVerified publisher1.0.01 of 2See more

fluentd-aggregator fluentd-aggregator 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,776
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,548
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

4,136

Container images carrying it

2,071 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
perl@5.36.0-7
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
perl@5.40.1-7ubuntu0.1
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
perl@5.36.0-7+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
perl@5.30.0-9ubuntu0.2
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
perl@5.36.0-7
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
perl@5.36.0-7+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
perl@5.36.0-7+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.