StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,411
of 17,792 indexed, latest versions
Container images
2,391
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,411 of 17,792 indexed charts deploy, on 2,391 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,370
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,411 by stars
ChartLatestAffected imagesRadar Score
pagessunilb2590-pages1.0.02 of 3See more

pages sunilb2590-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,262
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,474
svc-lb-muxsvc-lb-mux0.1.31 of 1See more

svc-lb-mux svc-lb-mux 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
perl@5.40.1-6
no fix listed

Open the chart page →

1,454
convert-datasvtechVerified publisher0.13.21 of 3See more

convert-data svtech 0.13.2

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

7,659
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
perl@5.40.1-6
no fix listed

Open the chart page →

4,711
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
perl@5.34.0-3ubuntu1
no fix listed

Open the chart page →

12,122
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

12,732
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

10,980
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,542
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

5,891
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,197
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
perl@5.34.0-3ubuntu1
no fix listed

Open the chart page →

12,122
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

18,853
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-2.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

14,061
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

8,263
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
yandex/clickhouse-server:latest1cbf75aabe1e
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

8,581
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
perl@5.40.1-6
no fix listed

Open the chart page →

3,276
topolvmsyself1.3.01 of 1See more

topolvm syself 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

3,599
vaultwardensyself1.0.01 of 1See more

vaultwarden syself 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vaultwarden/server:latest094b5689ed81
perl@5.40.1-6
no fix listed

Open the chart page →

1,766
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,285
nginx-charttaeseon-nginx0.1.01 of 1See more

nginx-chart taeseon-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,861
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

4,910
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:stablecb92301e719d
perl@5.40.1-6
no fix listed

Open the chart page →

4,027
super-mariotechpreta0.1.11 of 1See more

super-mario techpreta 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
nirmalnaveen/supermario:latest8541a39162f3
perl@5.36.0-7
no fix listed

Open the chart page →

6,338
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,139
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,606
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,551
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
perl@5.34.0-3ubuntu1
no fix listed
xeladock/nginx2:latestc259a67b1dff
perl@5.34.0-3ubuntu1
no fix listed

Open the chart page →

17,661
tensorzerotensorzero2026.6.02 of 2See more

tensorzero tensorzero 2026.6.0

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
tensorzero/gateway:2026.6.0c939db4f27e4
perl@5.40.1-6
no fix listed
tensorzero/ui:2026.6.0f2563d54724e
perl@5.40.1-6
no fix listed

Open the chart page →

4,033
supabaseteochenglim0.1.24 of 13See more

supabase teochenglim 0.1.2

4 of the 13 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/kong:latest2a8cf3b110cd
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
supabase/logflare:latest49bfe526f1b4
perl@5.40.1-6
no fix listed
supabase/realtime:latestd3aa0c86c7b3
perl@5.40.1-6
no fix listed
supabase/studio:latest94a2a9d2906e
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,796
pagestest43221.0.02 of 3See more

pages test4322 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,262
flask-contactstest-configmap1.0.12 of 3See more

flask-contacts test-configmap 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
perl@5.40.1-6
no fix listed
shashkist/flask-contacts-app:latest581de1fd6084
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,823
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,727
functionstest-helm-chart-hoanganht1k27Verified publisher0.1.11 of 1See more

functions test-helm-chart-hoanganht1k27 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,861
myfirstcharttest-helm-charts0.2.01 of 1See more

myfirstchart test-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,861
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,420
chatqnatest-opea1.0.08 of 11See more

chatqna test-opea 1.0.0

8 of the 11 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/chatqna:1.038c51b791efa
perl@5.36.0-7+deb12u1
no fix listed
opea/embedding-tei:1.05c9639de61c1
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed
opea/reranking-tei:1.0e48613afb191
perl@5.36.0-7+deb12u1
no fix listed
opea/retriever-redis:1.0eb746b263705
perl@5.36.0-7+deb12u1
no fix listed
redis/redis-stack:7.2.0-v91c5f43fddcdd
perl@5.34.0-3ubuntu1.3
no fix listed
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

39,419
codegentest-opea1.0.04 of 5See more

codegen test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/codegen:1.058f91683892d
perl@5.36.0-7+deb12u1
no fix listed
opea/codegen-ui:1.02bee4eb66f3e
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

29,001
codetranstest-opea1.0.04 of 5See more

codetrans test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/codetrans:1.0e2436483b73d
perl@5.36.0-7+deb12u1
no fix listed
opea/codetrans-ui:1.03ef121f34610
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

28,574
docsumtest-opea1.0.04 of 5See more

docsum test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
perl@5.36.0-7+deb12u1
no fix listed
opea/docsum:1.03eaa91849512
perl@5.36.0-7+deb12u1
no fix listed
opea/docsum-ui:1.07f854e9bffaf
perl@5.36.0-7+deb12u1
no fix listed
opea/llm-docsum-tgi:1.002f9e8fa5d71
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

29,049
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,223
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,259
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,757
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

5,677
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,023
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,236
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,656
teitest-opea1.0.01 of 1See more

tei test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,308
teireranktest-opea1.0.01 of 1See more

teirerank test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,308
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,404

Container images carrying it

2,391 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/kubectl:1.301249fc292e84
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.3164614ef8290f
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/kube-state-metrics:204a3044b384b
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/mariadb:latestbbd4e17f1ef8
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/mariadb-galera:11.3.2-debian-12-r9aee9c668098f
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/memcached:1.6.29-debian-12-r4ff0e7239c17c
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/mongodb:latestb0652af9c8d0
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/nginx:1.27.1934d1acd5ca8
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/openldap:2.6.8-debian-12-r16e412c178ef9
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/pgbouncer:1.23.192356da09704
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/postgresql:16.4.03ba6e6f11388
perl@5.36.0-7+deb12u1
no fix listed
1
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
perl@5.36.0-7+deb12u2
no fix listed
1
bitnamilegacy/postgresql:16.2.0-debian-12-r890fda44bfa42
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.