StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,414
of 17,790 indexed, latest versions
Container images
2,398
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,414 of 17,790 indexed charts deploy, on 2,398 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,377
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,414 by stars
ChartLatestAffected imagesRadar Score
postgresscalified-postgresVerified publisher18.4.01 of 1See more

postgres scalified-postgres 18.4.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
perl@5.40.1-6
no fix listed

Open the chart page →

1,684
factorioschichtelVerified publisher0.1.11 of 1See more

factorio schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
perl@5.40.1-6
no fix listed

Open the chart page →

2,994
mindustryschichtelVerified publisher0.1.11 of 1See more

mindustry schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
pschichtel/mindustry-server:v145.1b543e9c2d371
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

3,268
photonschichtelVerified publisher0.2.01 of 1See more

photon schichtel 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rtuszik/photon-docker:2.4.021549c60f9e6
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,870
s3-backupschichtelVerified publisher0.10.01 of 1See more

s3-backup schichtel 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
perl@5.40.1-6
no fix listed

Open the chart page →

2,372
satisfactoryschichtelVerified publisher0.3.31 of 1See more

satisfactory schichtel 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.9464d11e36e10
perl@5.34.0-3ubuntu1.4
no fix listed

Open the chart page →

3,567
vaultwardenschichtelVerified publisher0.9.21 of 1See more

vaultwarden schichtel 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
perl@5.40.1-6
no fix listed

Open the chart page →

1,766
wordpressschichtelVerified publisher0.10.102 of 2See more

wordpress schichtel 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/wordpress:6.9.4-fpmad4a8bae2eb4
perl@5.40.1-6
no fix listed
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
perl@5.40.1-6
no fix listed

Open the chart page →

8,275
otterwikischmitzis0.1.01 of 1See more

otterwiki schmitzis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
redimp/otterwiki:2778bf30da3da
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,246
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

6,167
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
typesense/typesense:0.25.1035ccfbc3fd8
perl@5.34.0-3ubuntu1.2
no fix listed

Open the chart page →

4,112
jellyfinschoolguys-helmcharts0.4.21 of 1See more

jellyfin schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.81694ff069f0c
perl@5.40.1-6
no fix listed

Open the chart page →

3,022
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
perl@5.40.1-7build1
no fix listed

Open the chart page →

10,445
satisfactory-serverschoolguys-helmcharts0.1.81 of 1See more

satisfactory-server schoolguys-helmcharts 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

3,469
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,916
unboundschoolguys-helmcharts0.1.11 of 1See more

unbound schoolguys-helmcharts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
mvance/unbound:1.20.04bf67b567f39
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,126
wyoming-faster-whisperschoolguys-helmcharts0.1.41 of 1See more

wyoming-faster-whisper schoolguys-helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rhasspy/wyoming-whisper:3.5.0308b7959a925
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,319
wyoming-piperschoolguys-helmcharts0.1.41 of 1See more

wyoming-piper schoolguys-helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rhasspy/wyoming-piper:2.3.169b7f797ae3a
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,892
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,723
search-proxysearch-proxy2026.38.01 of 1See more

search-proxy search-proxy 2026.38.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
perl@5.40.1-6
no fix listed

Open the chart page →

1,286
seawise-dashboardseawiseVerified publisher1.7.11 of 1See more

seawise-dashboard seawise 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
shwcloud/seawise-backup:v1.7.1a97479a54df4
perl@5.40.1-6
no fix listed

Open the chart page →

1,102
pagessekharpkube1.0.02 of 3See more

pages sekharpkube 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

23,041
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
perl@0:1.28-419.el8_4.1
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-Thread-Queue@3.13-1.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
0:3.14-457.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

22,349
postgresself-hosters-by-nightVerified publisher0.14.31 of 1See more

postgres self-hosters-by-night 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
perl@5.40.1-6
no fix listed

Open the chart page →

2,397
valkeyself-hosters-by-nightVerified publisher0.1.01 of 1See more

valkey self-hosters-by-night 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
valkey/valkey:9.1.164e361b630ec
perl@5.40.1-6
no fix listed

Open the chart page →

829
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.16d210dc69321e
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

10,976
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

3,335
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

5,500
service-exampleservice-example-10.1.02 of 7See more

service-example service-example-1 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

9,091
serviceexampleserviceexample-chart0.3.03 of 4See more

serviceexample serviceexample-chart 0.3.0

3 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed
tibyandocker/serviceexample:latesta4ad592cea84
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,018
serviceexampleservice-example-helm-chart0.1.02 of 4See more

serviceexample service-example-helm-chart 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

2,292
service-exampleservice-example-jt0.1.11 of 9See more

service-example service-example-jt 0.1.1

1 of the 9 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
janzo83/serviceexample:latestfb3c4ac36f3e
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,201
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,062
my-nginx-appsherif-nginx-app0.1.01 of 1See more

my-nginx-app sherif-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
shopwareshopware-storeVerified publisher2.1.21 of 5See more

shopware shopware-store 2.1.2

1 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
valkey/valkey:83fbd2e3e4b6e
perl@5.40.1-6
no fix listed

Open the chart page →

4,091
pagesshrutiujlan-pages1.0.02 of 3See more

pages shrutiujlan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.43a82e1f56c8f
perl@5.40.1-6
no fix listed

Open the chart page →

2,662
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

11,711
postgresqlsignoz0.0.21 of 1See more

postgresql signoz 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
perl@5.40.1-6
no fix listed

Open the chart page →

1,649
local-static-provisionersig-storage-local-static-provisioner2.9.01 of 1See more

local-static-provisioner sig-storage-local-static-provisioner 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,254
counter-dhlsikademo0.3.03 of 3See more

counter-dhl sikademo 0.3.0

3 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed
ondrejsika/counter:latestd95eaeee2172
perl@5.40.1-6
no fix listed
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,887
gordy-redissikademo0.1.01 of 1See more

gordy-redis sikademo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

978
test-hello-worldsikademo0.1.01 of 1See more

test-hello-world sikademo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
perl@5.40.1-6
no fix listed

Open the chart page →

1,189
hello-worldsikalabs0.17.01 of 1See more

hello-world sikalabs 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
perl@5.40.1-6
no fix listed

Open the chart page →

1,189
hello-world-examplesikalabs0.1.31 of 1See more

hello-world-example sikalabs 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
perl@5.40.1-6
no fix listed

Open the chart page →

1,189
kubernetes-dashboard-gatewaysikalabs0.1.01 of 1See more

kubernetes-dashboard-gateway sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
wordpress-mysqlsikalabs0.1.21 of 2See more

wordpress-mysql sikalabs 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
perl@5.40.1-6
no fix listed

Open the chart page →

3,893
simple-websimple-webVerified publisher1.1.11 of 1See more

simple-web simple-web 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
bitwardensinextraVerified publisher0.10.21 of 1See more

bitwarden sinextra 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
perl@5.40.1-6
no fix listed

Open the chart page →

1,766

Container images carrying it

2,398 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
perl@5.36.0-7+deb12u3
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
no fix listed
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
perl@5.36.0-7+deb12u3
no fix listed
3
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
perl@5.40.1-7ubuntu0.3
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
perl@5.36.0-7+deb12u1
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
perl@5.34.0-3ubuntu1.1
no fix listed
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
perl@5.30.0-9ubuntu0.2
no fix listed
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
perl@5.22.1-9ubuntu0.9
no fix listed
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
perl@5.34.0-3ubuntu1.1
no fix listed
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
perl@5.36.0-7+deb12u3
no fix listed
3
actualbudget/actual-server:26.9.0552beab3dec8
perl@5.36.0-7+deb12u3
no fix listed
2
alazidis/kube-netlag:1.1.00e8c84152201
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
2
apache/apisix:3.18.0-ubuntu9ee5df1611f9
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
apache/nifi-registry:1.26.07cdfd8deec92
perl@5.34.0-3ubuntu1.3
no fix listed
2
apache/rocketmq:5.4.0319cd8a81ed1
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/etcd:latest99b408c15272
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
perl@5.36.0-7+deb12u1
no fix listed
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
perl@5.36.0-7+deb12u1
no fix listed
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/redis:latest5927ff3702df
perl@5.36.0-7+deb12u2
no fix listed
2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
perl@5.36.0-7+deb12u2
no fix listed
2
bitnami/minideb:latestab4d5b45116e
perl@5.40.1-6
no fix listed
2
blockstack/stacks-core:3.2.0.0.0f79944317326
perl@5.36.0-7+deb12u2
no fix listed
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
perl@5.40.1-6
no fix listed
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
perl@5.36.0-7+deb12u1
no fix listed
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
perl@5.40.1-6
no fix listed
2
clickhouse/clickhouse-server:24.2ed9640bfff07
perl@5.30.0-9ubuntu0.5
no fix listed
2
cribl/cribl:4.19.2044f9a5fac9a
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
dagster/user-code-example:1.13.225947f9ae481c
perl@5.40.1-6
no fix listed
2
datagrok/grok_connect:latestf5876d3aebb8
perl@5.34.0-3ubuntu1.7
no fix listed
2
emberstack/kubernetes-reflector:10.0.6551dbd5880929
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
eqalpha/keydb:latest6537505c4235
perl@5.30.0-9ubuntu0.4
no fix listed
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
perl@5.30.0-9ubuntu0.4
no fix listed
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
perl@5.40.1-6
no fix listed
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
perl@5.40.1-6
no fix listed
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
perl@5.26.1-6ubuntu0.3
no fix listed
2
freikin/dawarich:1.14.511826c67e4b1
perl@5.40.1-6+deb13u1
no fix listed
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
perl@5.30.0-9ubuntu0.2
no fix listed
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
perl@5.30.0-9ubuntu0.2
no fix listed
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
perl@5.30.0-9ubuntu0.2
no fix listed
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.