StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,403
of 17,797 indexed, latest versions
Container images
2,378
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,403 of 17,797 indexed charts deploy, on 2,378 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,357
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,403 by stars
ChartLatestAffected imagesRadar Score
parcelapp-mcpobeoneVerified publisher0.1.01 of 1See more

parcelapp-mcp obeone 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
perl@5.40.1-6
no fix listed

Open the chart page →

872
ocellusaiocellusaiVerified publisher0.1.121 of 2See more

ocellusai ocellusai 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
perl@5.40.1-6
no fix listed

Open the chart page →

1,192
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
perl@5.40.1-6
no fix listed

Open the chart page →

17,161
octantisoctantis0.1.01 of 1See more

octantis octantis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/vinny1892/octantis:latest45459c0910fc
perl@5.40.1-6
no fix listed

Open the chart page →

2,590
mockoidcoidcmockVerified publisher0.0.11 of 1See more

mockoidc oidcmock 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
marcoimme/oidcmock:latestb6035c0721a8
perl@5.40.1-6
no fix listed

Open the chart page →

2,328
web-chartoje-ktcloudlab0.1.01 of 1See more

web-chart oje-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,861
ojp-serverojp0.1.51 of 1See more

ojp-server ojp 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rrobetti/ojp:0.1.0-beta1141bd88232b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,644
automx2oleds-helm-chartsVerified publisher1.0.51 of 1See more

automx2 oleds-helm-charts 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
oled01/automx2:2025.1.105d3e398e675
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

5,352
cmsmsoleds-helm-chartsVerified publisher0.1.61 of 1See more

cmsms oleds-helm-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

2,879
db-backupoleds-helm-chartsVerified publisher0.1.01 of 1See more

db-backup oleds-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
oled01/db-backup:0.1.06302fd2b5333
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

8,140
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
perl@5.34.0-3ubuntu1.2
no fix listed

Open the chart page →

9,083
laravel-appoli-the-devVerified publisher2.0.171 of 1See more

laravel-app oli-the-dev 2.0.17

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
perl@5.40.1-6
no fix listed

Open the chart page →

2,841
node-appoli-the-devVerified publisher1.0.01 of 1See more

node-app oli-the-dev 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/node:22-bookworm-slim83f487e0a634
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,179
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
perl@5.40.1-6
no fix listed

Open the chart page →

4,664
cron-jobonechart-slVerified publisher0.73.71 of 1See more

cron-job onechart-sl 0.73.7

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/debian:stable-slim04634311a8d5
perl@5.40.1-6
no fix listed

Open the chart page →

985
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

6,108
ontoserverontoserverVerified publisher0.5.21 of 2See more

ontoserver ontoserver 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
perl@5.40.1-6
no fix listed

Open the chart page →

1,667
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
perl@5.36.0-7
no fix listed

Open the chart page →

9,766
opentickopenchartVerified publisher0.1.01 of 1See more

opentick openchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:1.25.5a484819eb602
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,716
jobopen-charts2.0.01 of 1See more

job open-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

749
bbsimopencord4.8.111 of 1See more

bbsim opencord 4.8.11

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
voltha/bbsim:1.16.7d90403d58016
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

3,915
bbsim-sadis-serveropencord0.3.51 of 1See more

bbsim-sadis-server opencord 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
voltha/bbsim-sadis-server:0.4.0762b272d439e
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

3,729
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
perl@5.26.1-6ubuntu0.3
no fix listed
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

63,509
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
perl@5.22.1-9ubuntu0.6
no fix listed
omecproject/onos-progran:1.0.05715e5648aa0
perl@5.22.1-9ubuntu0.2
no fix listed
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

88,857
comac-cuopencord0.1.11 of 4See more

comac-cu opencord 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
perl@5.26.1-6
no fix listed

Open the chart page →

8,065
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

26,316
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

15,738
mcord-cdn-remoteopencord0.1.62 of 2See more

mcord-cdn-remote opencord 0.1.6

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
perl@5.22.1-9ubuntu0.6
no fix listed
woojoong/wowza:latestec230db19652
perl@5.26.1-6ubuntu0.2
no fix listed

Open the chart page →

42,879
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

29,359
mcord-control-planeopencord0.2.22 of 5See more

mcord-control-plane opencord 0.2.2

2 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
perl@5.22.1-9ubuntu0.5
no fix listed
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
perl@5.26.1-6
no fix listed

Open the chart page →

15,684
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
perl@5.26.1-6ubuntu0.3
no fix listed
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

14,574
omec-control-planeopencord0.1.315 of 8See more

omec-control-plane opencord 0.1.31

5 of the 8 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
omecproject/c3po-hss:master-latest638671ef4842
perl@5.22.1-9ubuntu0.9
no fix listed
omecproject/c3po-hssdb:master-latest28a90cc26716
perl@5.30.0-9ubuntu0.2
no fix listed
omecproject/mme-exporter:paging-latestbcc5f19fd676
perl@5.26.1-6ubuntu0.3
no fix listed
omecproject/ngic-cp:central-cp-multi-upfs-latest24a389a0a4fe
perl@5.26.1-6ubuntu0.3
no fix listed
omecproject/openmme:master-latest64776cb9edb3
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

40,941
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

12,953
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
perl@5.22.1-9ubuntu0.2
no fix listed

Open the chart page →

38,966
ovspluginopencord1.0.21 of 1See more

ovsplugin opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
gopinatht/ovs-plugin-installer:latest632cb2e9c399
perl@5.22.1-9ubuntu0.3
no fix listed

Open the chart page →

4,180
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

12,646
sebaopencord1.0.06 of 17See more

seba opencord 1.0.0

6 of the 17 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
perl@5.22.1-9ubuntu0.2
no fix listed
voltha/voltha-cli:1.6.0c4e41e92f046
perl@5.22.1-9ubuntu0.5
no fix listed
voltha/voltha-envoy:1.6.059ab2a00f712
perl@5.18.2-2ubuntu1.1
no fix listed
voltha/voltha-netconf:1.6.037f80524c207
perl@5.22.1-9ubuntu0.5
no fix listed
voltha/voltha-ofagent:1.6.09ee8c1f4428c
perl@5.22.1-9ubuntu0.5
no fix listed
voltha/voltha-voltha:1.6.0ff596b62de59
perl@5.22.1-9ubuntu0.5
no fix listed

Open the chart page →

94,117
voltha-infraopencord2.14.04 of 10See more

voltha-infra opencord 2.14.0

4 of the 10 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
perl@5.26.1-6ubuntu0.3
no fix listed
library/ubuntu:16.041f1a2d56de1d
perl@5.22.1-9ubuntu0.9
no fix listed
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
perl@5.26.1-6ubuntu0.7
no fix listed
voltha/voltha-onos:5.1.8e038acb950d3
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

41,148
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

11,064
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
perl@5.34.0-3ubuntu1.7
no fix listed

Open the chart page →

1,744
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

5,083
openlit-controlleropenlit0.10.01 of 1See more

openlit-controller openlit 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,384
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

3,472
llm-stackopenproject-helm-chartsVerified publisher1.1.02 of 2See more

llm-stack openproject-helm-charts 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/apisix:3.16.0-ubuntu5e47692cac00
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
library/python:3.12-slim78387bc3881b
perl@5.40.1-6
no fix listed

Open the chart page →

2,009
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-Compress-Raw-Bzip2@2.081-1.el8
perl-Compress-Raw-Zlib@2.081-1.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Digest-SHA@1:6.02-1.el8
perl-Encode@4:2.97-3.el8
perl-Encode-Locale@1.05-10.module+el8.3.0+6498+9eecfe51
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-2.el8
perl-IO-Compress@2.081-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:2.096-1.module+el8.10.0+21354+3ad137bb
0:2.096-2.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
1:6.02-2.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:1.05-10.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:2.096-2.module+el8.10.0+24402+ce90c7a0
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

12,185
bpjstk-serviceopenshift1.0.01 of 6See more

bpjstk-service openshift 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-3.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

35,119
fineractopenshift0.1.12 of 4See more

fineract openshift 0.1.1

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

7,889
sohaopensohaVerified publisher0.1.91 of 2See more

soha opensoha 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
perl@5.40.1-6
no fix listed

Open the chart page →

1,799
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

15,622
terminalsopen-webui0.7.02 of 2See more

terminals open-webui 0.7.0

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/open-webui/terminals:latest5d2fd44366a4
perl@5.40.1-6
no fix listed
ghcr.io/open-webui/terminals-operator:latest6287ce8be502
perl@5.40.1-6
no fix listed

Open the chart page →

2,060

Container images carrying it

2,378 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
istio/proxyv2:1.9.687a9db561d2e
perl@5.26.1-6ubuntu0.5
no fix listed
1
istio/proxyv2:1.10.088c6c693e67a
perl@5.26.1-6ubuntu0.5
no fix listed
1
istio/proxyv2:1.14.1df69c1a7af7c
perl@5.30.0-9ubuntu0.2
no fix listed
1
istio/ztunnel:1.25.005f3972d80a9
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.4
1
itzg/bungeecord:latest1c59f9631f3b
perl@5.40.1-7ubuntu0.1
no fix listed
1
ixsystems/truecommand:3.2.019c218455cd2
perl@5.40.1-6
no fix listed
1
jacobalberty/unifi:v7.1.664a3616625dda
perl@5.26.1-6ubuntu0.5
no fix listed
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
perl@5.26.1-6ubuntu0.7
no fix listed
1
jacobalberty/unifi:5.10.19c409924e2463
perl@5.22.1-9ubuntu0.6
no fix listed
1
jaedb/iris:latest048cfbf58d57
perl@5.36.0-7+deb12u2
no fix listed
1
jakowenko/double-take:1.6.0b858bac9e32a
perl@5.30.0-9ubuntu0.2
no fix listed
1
janzo83/serviceexample:latestfb3c4ac36f3e
perl@5.36.0-7+deb12u3
no fix listed
1
jbtronics/part-db1:latest5db71f6db59d
perl@5.36.0-7+deb12u3
no fix listed
1
jedi132000/nextapp:latestdc2a81e92f23
perl@5.30.0-9ubuntu0.3
no fix listed
1
jellyfin/jellyfin:10.11.81694ff069f0c
perl@5.40.1-6
no fix listed
1
jellyfin/jellyfin:10.11.717285f9cce63
perl@5.40.1-6
no fix listed
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
perl@5.36.0-7+deb12u1
no fix listed
1
jellyfin/jellyfin:10.11.6333b64771663
perl@5.40.1-6
no fix listed
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
perl@5.36.0-7+deb12u1
no fix listed
1
jellyfin/jellyfin:10.10.77ae36aab93ef
perl@5.36.0-7+deb12u1
no fix listed
1
jellyfin/jellyfin:10.10.696b09723b22f
perl@5.36.0-7+deb12u1
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
perl@5.36.0-7+deb12u1
no fix listed
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
perl@5.36.0-7+deb12u1
no fix listed
1
jertel/elastalert2:2.31.03cbf63f9b7dc
perl@5.40.1-6
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
perl@5.30.0-9ubuntu0.5
no fix listed
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
perl@5.36.0-7+deb12u1
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
perl@5.30.0-9ubuntu0.5
no fix listed
1
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
perl@5.36.0-7+deb12u1
no fix listed
1
jmferrer/azure-devops-agent:latest030f68ec6998
perl@5.22.1-9ubuntu0.6
no fix listed
1
jodogne/orthanc-plugins:latest6ff510aa29c2
perl@5.40.1-6
no fix listed
1
johly/airtrail:v3.11.19f702b91e0e7
perl@5.36.0-7+deb12u3
no fix listed
1
joplin/server:latest3f7b852959aa
perl@5.36.0-7+deb12u3
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
perl@5.36.0-7+deb12u3
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
perl@5.34.0-3ubuntu1.3
no fix listed
1
journeyapps/powersync-service:latestbf46f66e5dcc
perl@5.40.1-6
no fix listed
1
jpgouin/openldap:2.6.9-fixbfdd0088c776
perl@5.36.0-7+deb12u1
no fix listed
1
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
perl@5.36.0-7+deb12u1
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
perl@5.30.0-9ubuntu0.2
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
perl@5.30.0-9ubuntu0.2
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
perl@5.30.0-9ubuntu0.2
no fix listed
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
perl@5.34.0-3ubuntu1.3
no fix listed
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
perl@5.34.0-3ubuntu1.3
no fix listed
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
perl@5.34.0-3ubuntu1.3
no fix listed
1
kayrosuno/kping:latestf3bd44b29b0d
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
kennethreitz/httpbin:latest599fe5e50731
perl@5.26.1-6ubuntu0.2
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
perl@5.30.0-9ubuntu0.3
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
perl@5.36.0-7+deb12u3
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.