StackRadar

CVE-2026-48961

High

Advisory

Published 27 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,179
of 17,803 indexed, latest versions
Container images
2,075
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,179 of 17,803 indexed charts deploy, on 2,075 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.40.1-6+deb13u1, 5.40.1-6+e92,075
OSV records
DEBIAN-CVE-2026-48961UBUNTU-CVE-2026-48961ECHO-3bd6-6520-0759

Charts affected

2,179 by stars
ChartLatestAffected imagesRadar Score
jasperjasperVerified publisher1.0.2032 of 2See more

jasper jasper 1.0.203

2 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
perl@5.36.0-7+deb12u2
no fix listed
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,273
jasper-uijasperVerified publisher1.0.341 of 1See more

jasper-ui jasper 1.0.34

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,614
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

5,150
jellyfinjellyfin-helm10.9.101 of 1See more

jellyfin jellyfin-helm 10.9.10

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.9.1079fb3d73a3e9
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,548
jellyfinjellyfin--jellyfin-helm3.0.01 of 1See more

jellyfin jellyfin--jellyfin-helm 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.717285f9cce63
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,054
jx-app-jenkinsjenkins-x0.0.151 of 2See more

jx-app-jenkins jenkins-x 0.0.15

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,517
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

5,405
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

7,896
steamcmdjfwenischVerified publisher0.0.51 of 1See more

steamcmd jfwenisch 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
steamcmd/steamcmd:latest5028a25268e7
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

753
nginx-chartjinbok-nginx0.1.01 of 1See more

nginx-chart jinbok-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
nginx-chartjiungVerified publisher0.1.01 of 1See more

nginx-chart jiung 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
nginx-chartjongh09160.1.01 of 1See more

nginx-chart jongh0916 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
image-storage-servicejtektVerified publisher0.4.33 of 4See more

image-storage-service jtekt 0.4.3

3 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
no fix listed
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
perl@5.36.0-7+deb12u1
no fix listed
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

22,748
shinsei-managerjtektVerified publisher0.2.07 of 8See more

shinsei-manager jtekt 0.2.0

7 of the 8 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
perl@5.36.0-7+deb12u2
no fix listed
moreillon/group-manager:latest3caa8f710ee0
perl@5.36.0-7+deb12u3
no fix listed
moreillon/group-manager-front:latest5f0a38498271
perl@5.40.1-6
5.40.1-6+deb13u1
moreillon/user-manager:v5.0.2e1c9bfab5c16
perl@5.36.0-7
no fix listed
moreillon/user-manager-front:v5.0.3b067dbbbb6af
perl@5.36.0-7
no fix listed
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
perl@5.36.0-7+deb12u1
no fix listed
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

63,932
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
perl@5.36.0-7
no fix listed

Open the chart page →

16,710
searxngjuniorjpdj0.1.331 of 2See more

searxng juniorjpdj 0.1.33

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2c123e3715db6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

854
jupyter-hub-customizationsjupyter-jscVerified publisher0.27.171 of 4See more

jupyter-hub-customizations jupyter-jsc 0.27.17

1 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:1.291881968aff6f
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,444
jupyter-nginxjupyter-jscVerified publisher0.1.31 of 1See more

jupyter-nginx jupyter-jsc 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:1.29.49dd288848f44
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,563
jwks-mergejwks-merge0.1.01 of 2See more

jwks-merge jwks-merge 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,085
k10appk10app0.2.11 of 11See more

k10app k10app 0.2.1

1 of the 11 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,607
actual-budgetk8s-chartsVerified publisher0.2.31 of 1See more

actual-budget k8s-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
actualbudget/actual-server:25.3.158fecd9088b7
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,661
bitcoin-stackk8s-chartsVerified publisher1.0.11 of 1See more

bitcoin-stack k8s-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
blockstream/bitcoind:27.29472492530e3
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,462
deltabadgerk8s-chartsVerified publisher2.0.01 of 1See more

deltabadger k8s-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,725
jellyfink8s-chartsVerified publisher0.2.41 of 1See more

jellyfin k8s-charts 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.696b09723b22f
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,164
nostr-rs-relayk8s-chartsVerified publisher1.0.11 of 1See more

nostr-rs-relay k8s-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
scsibug/nostr-rs-relay:0.9.003f54bfbffff
perl@5.36.0-7
no fix listed

Open the chart page →

3,397
palworld-serverk8s-chartsVerified publisher1.2.11 of 1See more

palworld-server k8s-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
thijsvanloef/palworld-server-docker:v2.5.0b4ac9ee22483
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,523
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

57,344
flaresolverrk8s-home-lab-repo6.2.01 of 1See more

flaresolverr k8s-home-lab-repo 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

27,754
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,151
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

9,176
vaultwardenk8s-home-lab-repo6.2.31 of 1See more

vaultwarden k8s-home-lab-repo 6.2.3

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
vaultwarden/server:1.35.79a8eec71f4a5
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,896
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

9,865
librephotosk8sonlabVerified publisher1.1.63 of 7See more

librephotos k8sonlab 1.1.6

3 of the 7 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/redis:latest5927ff3702df
perl@5.36.0-7+deb12u2
no fix listed
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

14,969
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

7,445
kadeck-teamskadeck1.1.211 of 1See more

kadeck-teams kadeck 1.1.21

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
xeotek/kadeck:6.3.439a3b37a17c5
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

3,631
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

7,369
kagentkagent0.10.11 of 6See more

kagent kagent 0.10.1

1 of the 6 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
mcp/grafana:latest9362bcf6aa0e
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,064
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,622
jenkinskallakruparaju-jenkins1.0.01 of 1See more

jenkins kallakruparaju-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,517
kanrikanri0.1.01 of 1See more

kanri kanri 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/hypolia/kanri:0.1.2-rc4fa7d5cc7fb7d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,126
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,163
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

79,018
kbot-self-hostedkbot-self-hostedVerified publisher0.1.81 of 7See more

kbot-self-hosted kbot-self-hosted 0.1.8

1 of the 7 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.30206a6c708fc6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

33,021
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

8,915
web-chartkcilab0.1.01 of 1See more

web-chart kcilab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,282
kestra-starterkestraOfficialVerified publisher2.0.21 of 5See more

kestra-starter kestra 2.0.2

1 of the 5 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/postgres:17.5aadf2c0696f5
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,617
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
perl@5.22.1-9ubuntu0.9
no fix listed

Open the chart page →

8,832
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

64,463
phppgadminkfirfer0.1.121 of 1See more

phppgadmin kfirfer 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

10,326

Container images carrying it

2,075 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
perl@5.40.1-6
5.40.1-6+deb13u1
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
perl@5.40.1-7ubuntu0.1
no fix listed
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
perl@5.36.0-7+deb12u3
no fix listed
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
perl@5.36.0-7+deb12u3
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
perl@5.36.0-7
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
perl@5.40.1-7ubuntu0.1
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
perl@5.36.0-7+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
perl@5.30.0-9ubuntu0.2
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
perl@5.36.0-7
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
perl@5.36.0-7+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
perl@5.36.0-7+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.