StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,417
of 17,787 indexed, latest versions
Container images
2,395
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,417 of 17,787 indexed charts deploy, on 2,395 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,374
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,417 by stars
ChartLatestAffected imagesRadar Score
viya4-home-dir-builderselerityVerified publisher1.1.01 of 2See more

viya4-home-dir-builder selerity 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/python:3.12-slim78387bc3881b
perl@5.40.1-6
no fix listed

Open the chart page →

864
sentry-k8ssentry-k8sVerified publisher1.4.15 of 11See more

sentry-k8s sentry-k8s 1.4.1

5 of the 11 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
perl@5.34.0-3ubuntu1.4
no fix listed
library/postgres:16f1c3376c26f2
perl@5.40.1-6
no fix listed
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
perl@5.36.0-7+deb12u1
no fix listed
ghcr.io/getsentry/snuba:26.7.210f8d164109b
perl@5.40.1-6
no fix listed
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

16,194
seq-input-gelfseq-input-gelfVerified publisher0.3.11 of 2See more

seq-input-gelf seq-input-gelf 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
datalust/seq-input-gelf:3.0.441-x643de34aed5642
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

3,552
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
perl@5.36.0-7+deb12u2
no fix listed
dserio83/velero-watchdog:0.1.8d5deae589229
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

11,545
sigscale-csesigscale-cseOfficialVerified publisher1.4.221 of 1See more

sigscale-cse sigscale-cse 1.4.22

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sigscale/cse:latest67d0c886516b
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,185
sigscale-ocssigscale-ocsOfficialVerified publisher1.1.171 of 1See more

sigscale-ocs sigscale-ocs 1.1.17

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sigscale/ocs:latest3c1bdc9732e2
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,185
mssqlserver-2019simcube1.2.31 of 1See more

mssqlserver-2019 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

6,864
clickhousesinextraVerified publisher0.22.01 of 1See more

clickhouse sinextra 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3.1092098d3b31dd
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

2,013
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

4,250
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,920
gitlab-omnibusslamdev0.1.61 of 2See more

gitlab-omnibus slamdev 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
daedalusproject/base_kubectl:latest6f72b5119eda
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

2,849
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,934
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
perl@5.30.0-9ubuntu0.3
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
perl@5.30.0-9ubuntu0.3
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

46,028
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
perl@5.40.1-6
no fix listed
valkey/valkey:8.1.61f84517eca8e
perl@5.40.1-6
no fix listed

Open the chart page →

3,019
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
perl@5.40.1-6
no fix listed

Open the chart page →

14,504
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

2,320
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
perl@5.40.1-6
no fix listed

Open the chart page →

7,157
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
perl@5.36.0-7+deb12u3
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,390
rabbitmqsolidchartsVerified publisher0.7.51 of 2See more

rabbitmq solidcharts 0.7.5

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.5-managementffd1b50c522a
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,040
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,688
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

10,405
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

2,622
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,673
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

13,532
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

24,984
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
alazidis/stornx:1.1.1602d4f7f090c
perl@5.36.0-7+deb12u3
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

11,683
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,874
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
kong/kong:3.9.16addf50e6bd8
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
supabase/edge-runtime:v1.74.02781daf92394
perl@5.36.0-7+deb12u3
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
perl@5.36.0-7+deb12u3
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
perl@5.36.0-7+deb12u3
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

18,213
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

2,139
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
perl@5.40.1-6
no fix listed

Open the chart page →

3,253
mumblesyntaxerror404Verified publisher1.0.41 of 1See more

mumble syntaxerror404 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,138
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/haproxy:3.2de601ccc9a79
perl@5.40.1-6
no fix listed

Open the chart page →

836
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
perl@5.40.1-6+dhi4
no fix listed

Open the chart page →

2,553
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
perl@5.36.0-7
no fix listed

Open the chart page →

9,108
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
perl@5.36.0-7
no fix listed

Open the chart page →

9,108
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
perl@5.40.1-6
no fix listed

Open the chart page →

12,910
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,061
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
perl@5.40.1-6
no fix listed
kixote/typemilldigest-pinned628f79a08cc7
perl@5.40.1-6
no fix listed

Open the chart page →

5,402
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

1,908
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

3,804
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

3,804
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

12,137
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
perl@5.40.1-6
no fix listed
taigaio/taiga-protected:latestfd4568a97a59
perl@5.40.1-6
no fix listed

Open the chart page →

9,172
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,022
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
perl@5.40.1-6
no fix listed

Open the chart page →

2,282
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,058
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

5,239
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
perl@5.30.0-9ubuntu0.4
no fix listed
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

26,843

Container images carrying it

2,395 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
falcosecurity/falco-driver-loader:0.44.17df783d5269a
perl@5.36.0-7+deb12u3
no fix listed
1
federid/webhook:0.1.0fbfb7c6510a7
perl@5.36.0-7+deb12u1
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
perl@5.36.0-7+deb12u1
no fix listed
1
firefart/requesttracker:5.0.40d6249906d8c
perl@5.36.0-7
no fix listed
1
fireflyiii/core:version-6.6.6ae69fdd95cde
perl@5.40.1-6
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
perl@5.30.0-9ubuntu0.5
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
perl@5.36.0-7+deb12u2
no fix listed
1
flanksource/apm-hub:v0.0.471dacc3195bf9
perl@5.34.0-3ubuntu1.2
no fix listed
1
flanksource/batch-runner:v1.0.44689687a7cf95
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
perl@5.36.0-7+deb12u1
no fix listed
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
perl@5.36.0-7+deb12u1
no fix listed
1
flashcatcloud/categraf:latest42e6ab16472e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
flashcatcloud/nightingale:8.5.1421acb36181b
perl@5.40.1-6
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
perl@5.36.0-7+deb12u3
no fix listed
1
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
perl@5.40.1-6
no fix listed
1
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
perl@5.40.1-6
no fix listed
1
flyway/flyway:9.1545b5d7cdc75a
perl@5.30.0-9ubuntu0.3
no fix listed
1
fnzv/dump1090:latestb3079b95c336
perl@5.34.0-3ubuntu1.3
no fix listed
1
foldingathome/fah-gpu:latest5ef7742d1eb4
perl@5.26.1-6ubuntu0.5
no fix listed
1
folioci/mod-z3950:latest2493041ce880
perl@5.40.1-6
no fix listed
1
fosrl/pangolin:latest83a55f933b4d
perl@5.36.0-7+deb12u3
no fix listed
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
perl@5.26.1-6ubuntu0.3
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
perl@5.26.1-6ubuntu0.3
no fix listed
1
frankescobar/allure-docker-service:latestdc171ec796d5
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
free5gmano/nextepc-mongodb:latest36f806935519
perl@5.22.1-9ubuntu0.6
no fix listed
1
freedom98/flask:k3.0d7ce1533f297
perl@5.36.0-7+deb12u1
no fix listed
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
perl@5.34.0-3ubuntu1.5
no fix listed
1
freikin/dawarich:1.14.511826c67e4b1
perl@5.40.1-6+deb13u1
no fix listed
1
galaxy/cloudman-server:lateste5c265fe9fcd
perl@5.30.0-9ubuntu0.2
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
perl@5.18.2-2ubuntu1.4
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
perl@5.18.2-2ubuntu1.4
no fix listed
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
perl@5.36.0-7+deb12u2
no fix listed
1
galexrt/extended-ceph-exporter:v1.8.05373078a3a08
perl@5.40.1-6
no fix listed
1
gchq/accumulo:2.0.1c460bb587d6d
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
perl@5.26.1-6ubuntu0.7
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
perl@5.34.0-3ubuntu1.5
no fix listed
1
geopython/pycsw:3.0.0-beta284662ea6b78b
perl@5.36.0-7+deb12u3
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
perl@5.26.1-6ubuntu0.3
no fix listed
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
perl@5.30.0-9ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
perl@5.40.1-7ubuntu0.1
no fix listed
1
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
perl@5.40.1-7ubuntu0.1
no fix listed
1
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
perl@5.40.1-7ubuntu0.1
no fix listed
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
perl@5.30.0-9ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
perl@5.30.0-9ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
perl@5.40.1-7ubuntu0.1
no fix listed
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
perl@5.30.0-9ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
perl@5.40.1-7ubuntu0.1
no fix listed
1
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
perl@5.40.1-7ubuntu0.1
no fix listed
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
perl@5.30.0-9ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
perl@5.30.0-9ubuntu0.2
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.