StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,398
of 17,790 indexed, latest versions
Container images
2,371
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,398 of 17,790 indexed charts deploy, on 2,371 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,350
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,398 by stars
ChartLatestAffected imagesRadar Score
printserverhmediadeVerified publisher1.0.22 of 4See more

printserver hmediade 1.0.2

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
hmediade/printserver:latest481a552c8e1c
perl@5.34.0-3ubuntu1.3
no fix listed
hmediade/printserver-init:latest7f005eb6c718
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

10,918
home-ha-mockhome-ha-mockVerified publisher2.0.51 of 1See more

home-ha-mock home-ha-mock 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

3,054
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
perl@5.36.0-7
no fix listed

Open the chart page →

14,629
home-security-demohome-security-demoVerified publisher2.0.121 of 3See more

home-security-demo home-security-demo 2.0.12

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

3,137
paperlesshpVerified publisher0.1.23See more

paperless hp 0.1.2

3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
perl@5.40.1-7build1
no fix listed
gotenberg/gotenberg:8.3467097317623a
perl@5.40.1-6
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
perl@5.40.1-6
no fix listed

Open the chart page →

httpbin2022httpbin2022Verified publisher0.1.11 of 1See more

httpbin2022 httpbin2022 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
mshanley80/httpbin2022:latest5b189a70c0fb
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

8,732
eoloplanthttpd-eoloplant0.1.04 of 7See more

eoloplant httpd-eoloplant 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
perl@5.34.0-3ubuntu1.1
no fix listed
codeurjc/toposervice:v1.09fb4c11e6a49
perl@5.26.1-6ubuntu0.6
no fix listed
library/mongo:5.0.6-focal8e70544b6c76
perl@5.30.0-9ubuntu0.2
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

32,336
jenkinshuangchengwu-helm-chart0.1.01 of 2See more

jenkins huangchengwu-helm-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

733
mariadbhuangchengwu-helm-chart0.1.01 of 1See more

mariadb huangchengwu-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:latestdd9b303aed4f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,919
prometheushuangchengwu-helm-chart0.1.02 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
perl@5.34.0-3ubuntu1
no fix listed
apache/skywalking-ui:9.2.0295f1dc87d98
perl@5.34.0-3ubuntu1
no fix listed

Open the chart page →

16,482
skywalking-v1huangchengwu-helm-chart0.1.02 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
perl@5.30.0-9ubuntu0.2
no fix listed
apache/skywalking-ui:8.9.180530f0308a5
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

20,727
tdenginehuangchengwu-helm-chart3.0.21 of 1See more

tdengine huangchengwu-helm-chart 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
tdengine/tdengine:3.0.2.24140a4021ddb
perl@5.26.1-6ubuntu0.6
no fix listed

Open the chart page →

3,753
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,355
add-crismuxhydraVerified publisher0.9.31 of 1See more

add-crismux hydra 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,289
hydrahydraVerified publisher0.9.52 of 2See more

hydra hydra 0.9.5

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,038
isolated-vmhydraVerified publisher0.9.41 of 1See more

isolated-vm hydra 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,749
remove-crismuxhydraVerified publisher0.9.31 of 1See more

remove-crismux hydra 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,289
nginx-charthyomin-nginx0.1.01 of 1See more

nginx-chart hyomin-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
hyperglance-helmhyperglance-helmVerified publisher10.0.54 of 6See more

hyperglance-helm hyperglance-helm 10.0.5

4 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
hyperglance/init:wildfly467ad8491bc3
perl@5.34.0-3ubuntu1.5
no fix listed
hyperglance/init:postgres9fd5faf1fe80
perl@5.34.0-3ubuntu1.5
no fix listed
hyperglance/init:apacheb2f8c6d52623
perl@5.34.0-3ubuntu1.5
no fix listed
hyperglance/postgresql-v2:10.0.5eb4d383894b8
perl@5.34.0-3ubuntu1.9
no fix listed

Open the chart page →

11,171
nginx-charthyun-nginx0.1.01 of 1See more

nginx-chart hyun-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

7,184
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

7,902
iam-eks-user-mapperiam-eks-user-mapper1.6.01 of 1See more

iam-eks-user-mapper iam-eks-user-mapper 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
perl@5.40.1-6
no fix listed

Open the chart page →

1,649
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,770
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ibmcom/microclimate-theia:lateste17bdccc5030
perl@5.22.1-9ubuntu0.2
no fix listed
jenkins/jenkins:ltsc1e4c349365f
perl@5.40.1-6
no fix listed

Open the chart page →

57,728
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

12,632
ibm-swift-sampleibm-charts1.1.21 of 1See more

ibm-swift-sample ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ibmcom/icp-swift-sample:latestb5d8c6714dbc
perl@5.22.1-9ubuntu0.3
no fix listed

Open the chart page →

25,184
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
perl@5.22.1-9ubuntu0.5
no fix listed

Open the chart page →

19,309
ibm-ucv-prodibm-helm5.2.62 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

2 of the 16 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.27.1934d1acd5ca8
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/rabbitmq:4.1.2fac502149c40
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

11,975
icegateicegateVerified publisher0.1.13 of 3See more

icegate icegate 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/icegatetech/icegate-ingest:0.1.1bae3c441894a
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/icegatetech/icegate-maintain:0.1.193e85b2b76ee
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/icegatetech/icegate-query:0.1.17542b4e7fff2
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,332
codex-poolericoretechVerified publisher0.8.71See more

codex-pooler icoretech 0.8.7

1 container image this version deploys carries CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/icoretech/codex-pooler:0.7.81bebc7e4a770
perl@5.40.1-6
no fix listed

Open the chart page →

metamcpicoretechVerified publisher0.3.101 of 2See more

metamcp icoretech 0.3.10

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
perl@5.40.1-6
no fix listed

Open the chart page →

1,638
multicaicoretechVerified publisher0.4.431See more

multica icoretech 0.4.43

1 container image this version deploys carries CVE-2026-9538.

Container imageDigestPackageFixed in
pgvector/pgvector:pg17cf134a767f47
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

nextjsicoretechVerified publisher1.2.01 of 1See more

nextjs icoretech 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
tolgeeicoretechVerified publisher0.47.01See more

tolgee icoretech 0.47.0

1 container image this version deploys carries CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.369e8582b781c
perl@5.40.1-6
no fix listed

Open the chart page →

eoloserverihuertas2021-vmartinp2021-helm0.1.03 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
perl@5.26.1-6ubuntu0.6
no fix listed
library/mongo:5.0.6-focal8e70544b6c76
perl@5.30.0-9ubuntu0.2
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

27,812
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

9,032
ikigaiikigai-chartVerified publisher0.0.94 of 58See more

ikigai ikigai-chart 0.0.9

4 of the 58 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
perl@5.34.0-3ubuntu1.1
no fix listed
jupyterhub/k8s-hub:1.2.0e4770285aaf7
perl@5.30.0-9ubuntu0.2
no fix listed
library/zookeeper:3.8-temurin55d1e5b2e601
perl@5.34.0-3ubuntu1.2
no fix listed
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

37,844
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
perl@5.40.1-6
no fix listed

Open the chart page →

2,177
ilum-hive-metastoreilumVerified publisher1.2.01 of 2See more

ilum-hive-metastore ilum 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,586
ilum-marquezilumVerified publisher6.7.02 of 3See more

ilum-marquez ilum 6.7.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
perl@5.36.0-7+deb12u1
no fix listed
ilum/marquez:0.54.06e1d709d41f8
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

6,282
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
perl@5.40.1-6
no fix listed

Open the chart page →

2,748
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

11,838
web-chartimcherry57780.1.01 of 1See more

web-chart imcherry5778 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
onechartimioVerified publisher0.76.01 of 1See more

onechart imio 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
plausible-analyticsimioVerified publisher0.4.23 of 5See more

plausible-analytics imio 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

10,152
smtp4devimioVerified publisher0.1.11 of 1See more

smtp4dev imio 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rnwood/smtp4dev:3.6.1912304153668
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,205
apexkube-agentimprowisedVerified publisher1.4.01 of 2See more

apexkube-agent improwised 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31.02bf7f042e396
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

3,350
kore-boardimprowisedVerified publisher0.5.81 of 4See more

kore-board improwised 0.5.8

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
perl@5.26.1-6ubuntu0.6
no fix listed

Open the chart page →

16,226
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

5,360

Container images carrying it

2,371 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
perl@5.36.0-7+deb12u3
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
perl@5.36.0-7+deb12u3
no fix listed
3
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
perl@5.40.1-7ubuntu0.3
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
perl@5.36.0-7+deb12u1
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
perl@5.34.0-3ubuntu1.1
no fix listed
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
perl@5.30.0-9ubuntu0.2
no fix listed
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
perl@5.22.1-9ubuntu0.9
no fix listed
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
perl@5.34.0-3ubuntu1.1
no fix listed
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
perl@5.36.0-7+deb12u3
no fix listed
3
actualbudget/actual-server:26.9.0552beab3dec8
perl@5.36.0-7+deb12u3
no fix listed
2
alazidis/kube-netlag:1.1.00e8c84152201
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
2
apache/apisix:3.18.0-ubuntu9ee5df1611f9
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
apache/nifi-registry:1.26.07cdfd8deec92
perl@5.34.0-3ubuntu1.3
no fix listed
2
apache/rocketmq:5.4.0319cd8a81ed1
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/etcd:latest99b408c15272
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
perl@5.36.0-7+deb12u1
no fix listed
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
perl@5.36.0-7+deb12u1
no fix listed
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/redis:latest5927ff3702df
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
perl@5.36.0-7+deb12u2
no fix listed
2
bitnami/minideb:latestab4d5b45116e
perl@5.40.1-6
no fix listed
2
blockstack/stacks-core:3.2.0.0.0f79944317326
perl@5.36.0-7+deb12u2
no fix listed
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
perl@5.40.1-6
no fix listed
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
perl@5.36.0-7+deb12u1
no fix listed
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
perl@5.40.1-6
no fix listed
2
clickhouse/clickhouse-server:24.2ed9640bfff07
perl@5.30.0-9ubuntu0.5
no fix listed
2
cribl/cribl:4.19.2044f9a5fac9a
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
dagster/user-code-example:1.13.225947f9ae481c
perl@5.40.1-6
no fix listed
2
datagrok/grok_connect:latestf5876d3aebb8
perl@5.34.0-3ubuntu1.7
no fix listed
2
emberstack/kubernetes-reflector:10.0.6551dbd5880929
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
eqalpha/keydb:latest6537505c4235
perl@5.30.0-9ubuntu0.4
no fix listed
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
perl@5.30.0-9ubuntu0.4
no fix listed
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
perl@5.40.1-6
no fix listed
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
perl@5.40.1-6
no fix listed
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
perl@5.26.1-6ubuntu0.3
no fix listed
2
freikin/dawarich:1.14.511826c67e4b1
perl@5.40.1-6+deb13u1
no fix listed
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
perl@5.30.0-9ubuntu0.2
no fix listed
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
perl@5.30.0-9ubuntu0.2
no fix listed
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
perl@5.30.0-9ubuntu0.2
no fix listed
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.