StackRadar

CVE-2026-48961

High

Advisory

Published 27 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,179
of 17,803 indexed, latest versions
Container images
2,075
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,179 of 17,803 indexed charts deploy, on 2,075 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+39 more5.40.1-6+deb13u1, 5.40.1-6+e92,075
OSV records
DEBIAN-CVE-2026-48961UBUNTU-CVE-2026-48961ECHO-3bd6-6520-0759

Charts affected

2,179 by stars
ChartLatestAffected imagesRadar Score
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
perl@5.30.0-9build1
no fix listed

Open the chart page →

68,442
kube-prometheus-stackmesosphere-stable75.9.11 of 7See more

kube-prometheus-stack mesosphere-stable 75.9.1

1 of the 7 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

10,568
localpathprovisionermesosphere-stable0.1.21 of 1See more

localpathprovisioner mesosphere-stable 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
perl@5.22.1-9ubuntu0.5
no fix listed

Open the chart page →

18,113
multusmesosphere-stable0.1.11 of 1See more

multus mesosphere-stable 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.4-thick3c20900b5381
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,827
valkeymesosphere-stable3.0.221 of 1See more

valkey mesosphere-stable 3.0.22

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
bitnamilegacy/valkey:8.1.3-debian-12-r1a185655855b3
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

2,671
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

8,963
elasticmicroboxlabs0.3.01 of 1See more

elastic microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/elasticsearch:8.17.32cc40b15dff8
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

4,309
miot-harnessmicroboxlabs0.7.01 of 1See more

miot-harness microboxlabs 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,189
postgresmicroboxlabs0.3.01 of 1See more

postgres microboxlabs 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/postgres:16.6557fea37a744
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,947
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

5,179
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

4,649
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

67,705
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

11,352
parent-chartmid-proje0.1.01 of 3See more

parent-chart mid-proje 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
youssef11gaber10/flask-service:latest9c727fcfde76
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,823
teimilvus-helm1.6.01 of 1See more

tei milvus-helm 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,336
mini-blogmini-blog-helm0.1.02 of 3See more

mini-blog mini-blog-helm 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
perl@5.36.0-7+deb12u2
no fix listed
library/postgres:159b1d34adbce1
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

13,176
MINTmint8.0.24 of 15See more

MINT mint 8.0.2

4 of the 15 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1
library/redis:latest298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
perl@5.30.0-9ubuntu0.2
no fix listed
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

110,158
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,732
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

10,642
session-scalermiqm0.1.01 of 1See more

session-scaler miqm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
miqm/session-scaler:0.1.0c5c211717d9b
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,228
helmmirasys-chart0.1.02 of 4See more

helm mirasys-chart 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
perl@5.40.1-6
5.40.1-6+deb13u1
sepehrmdn/mirasys-assignment:1.0.12567228e33c8
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,448
simplewebappmlohrVerified publisher1.1.01 of 1See more

simplewebapp mlohr 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,879
mariadbmmontesVerified publisher0.3.01 of 1See more

mariadb mmontes 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/mariadb:10.7.307e06f2e7ae9
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

10,127
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,164
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,838
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,838
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

12,252
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

16,329
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,622
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

19,392
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

6,236
mollysocketmollysocketVerified publisher0.2.81 of 1See more

mollysocket mollysocket 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
perl@5.36.0-7
no fix listed

Open the chart page →

3,065
mollysocketmollysocket-wrenixVerified publisher0.1.141 of 2See more

mollysocket mollysocket-wrenix 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,546
mongo-compassmongo-compass-webVerified publisher1.1.41 of 1See more

mongo-compass mongo-compass-web 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.1f4f8fe4e21f1
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,805
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,442
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

5,234
moodlemoodle1.0.31 of 2See more

moodle moodle 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
cloudtooling/moodle:5.2.3f4f04e0fc401
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,993
camera-viewermoreillonVerified publisher0.2.12 of 4See more

camera-viewer moreillon 0.2.1

2 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
no fix listed
moreillon/camera-viewer:lateste418cc694bd5
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

11,700
group-managermoreillonVerified publisher0.4.42 of 3See more

group-manager moreillon 0.4.4

2 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
no fix listed
moreillon/group-manager-front:v3.3.1c9f85db3baa5
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,891
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
no fix listed

Open the chart page →

11,025
user-manager-mongodbmoreillonVerified publisher0.6.23 of 4See more

user-manager-mongodb moreillon 0.6.2

3 of the 4 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
no fix listed
moreillon/user-manager-front:v5.0.3b067dbbbb6af
perl@5.36.0-7
no fix listed
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
perl@5.36.0-7
no fix listed

Open the chart page →

25,873
user-manager-neo4jmoreillonVerified publisher0.9.74 of 6See more

user-manager-neo4j moreillon 0.9.7

4 of the 6 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
no fix listed
moreillon/group-manager-front:v3.3.1c9f85db3baa5
perl@5.36.0-7+deb12u1
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
perl@5.36.0-7
no fix listed
moreillon/user-manager-front:v5.1.06597e6b98d21
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

30,530
genericmorremeyer8.0.01 of 1See more

generic morremeyer 8.0.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/nginx:1.25.167f9a4f10d14
perl@5.36.0-7
no fix listed

Open the chart page →

6,852
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

96,742
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

15,924
codimdmt1905027.2.21 of 3See more

codimd mt190502 7.2.2

1 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

1,686
commafeedmt1905028.2.02 of 3See more

commafeed mt190502 8.2.0

2 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
perl@5.40.1-6
5.40.1-6+deb13u1
library/postgres:184ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,796
filestashmt1905024.0.01 of 1See more

filestash mt190502 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
machines/filestash:latest0b8fc005e52e
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

3,568
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,032
keycloakmt1905021.4.61 of 3See more

keycloak mt190502 1.4.6

1 of the 3 container images this version deploys carry CVE-2026-48961.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
perl@5.40.1-6
5.40.1-6+deb13u1

Open the chart page →

2,965

Container images carrying it

2,075 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
perl@5.40.1-6
5.40.1-6+deb13u1
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
perl@5.40.1-7ubuntu0.1
no fix listed
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
perl@5.36.0-7+deb12u3
no fix listed
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
perl@5.36.0-7+deb12u3
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
perl@5.36.0-7
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
perl@5.40.1-7ubuntu0.1
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
perl@5.36.0-7+deb12u3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
perl@5.36.0-7+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
perl@5.30.0-9ubuntu0.2
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
perl@5.40.1-6
5.40.1-6+deb13u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
perl@5.36.0-7
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
perl@5.36.0-7+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
perl@5.36.0-7+deb12u2
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
perl@5.36.0-7+deb12u3
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.