StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,396
of 17,803 indexed, latest versions
Container images
2,366
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,396 of 17,803 indexed charts deploy, on 2,366 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+46 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,345
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,396 by stars
ChartLatestAffected imagesRadar Score
entehelmforgeVerified publisher1.0.22 of 4See more

ente helmforge 1.0.2

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
perl@5.40.1-6
no fix listed

Open the chart page →

4,283
fastmcp-serverhelmforgeVerified publisher1.7.41 of 1See more

fastmcp-server helmforge 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.11.2fcb7017327d6
perl@5.40.1-6
no fix listed

Open the chart page →

3,306
generichelmforgeVerified publisher3.1.51 of 1See more

generic helmforge 3.1.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:1.31.505b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,861
ghosthelmforgeVerified publisher1.2.71 of 3See more

ghost helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,493
hoppscotchhelmforgeVerified publisher1.1.111 of 2See more

hoppscotch helmforge 1.1.11

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

2,094
immichhelmforgeVerified publisher1.2.84 of 5See more

immich helmforge 1.2.8

4 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
no fix listed
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
perl@5.40.1-6
no fix listed
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

11,180
jenkinshelmforgeVerified publisher1.0.91 of 1See more

jenkins helmforge 1.0.9

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jenkins/jenkins:2.568.3-lts-jdk21c1e4c349365f
perl@5.40.1-6
no fix listed

Open the chart page →

2,498
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,471
komgahelmforgeVerified publisher1.4.151 of 1See more

komga helmforge 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

2,305
listmonkhelmforgeVerified publisher1.1.141 of 3See more

listmonk helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

2,881
matterbridgehelmforgeVerified publisher1.0.31 of 1See more

matterbridge helmforge 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
luligu/matterbridge:3.10.9c01108d904ec
perl@5.40.1-6
no fix listed

Open the chart page →

926
mcp-serverhelmforgeVerified publisher1.0.01 of 1See more

mcp-server helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.2.061f759a1421f
perl@5.40.1-6
no fix listed

Open the chart page →

3,455
medikeephelmforgeVerified publisher2.0.12 of 3See more

medikeep helmforge 2.0.1

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
ghcr.io/afairgiant/medikeep:v0.70.04c28334f3c79
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,463
memcachedhelmforgeVerified publisher1.0.81 of 1See more

memcached helmforge 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
perl@5.40.1-6
no fix listed

Open the chart page →

1,081
metabasehelmforgeVerified publisher1.2.291 of 3See more

metabase helmforge 1.2.29

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

1,694
middlewarehelmforgeVerified publisher1.2.63 of 4See more

middleware helmforge 1.2.6

3 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
no fix listed
middlewareeng/middleware:0.3.1747d880812f1
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

9,801
moodlehelmforgeVerified publisher1.1.02 of 2See more

moodle helmforge 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

6,325
netboxhelmforgeVerified publisher2.0.13 of 4See more

netbox helmforge 2.0.1

3 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
no fix listed
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

4,396
nextcloudhelmforgeVerified publisher1.0.03 of 3See more

nextcloud helmforge 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nextcloud:34.0.4-apachede4ad9389386
perl@5.40.1-6
no fix listed
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

7,244
notediscoveryhelmforgeVerified publisher2.0.11 of 1See more

notediscovery helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/gamosoft/notediscovery:0.31.5c06aa0fa9a85
perl@5.40.1-6
no fix listed

Open the chart page →

1,270
opencuthelmforgeVerified publisher1.1.92 of 5See more

opencut helmforge 1.1.9

2 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

3,799
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
perl@5.40.1-6
no fix listed

Open the chart page →

2,570
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
perl@5.40.1-6
no fix listed

Open the chart page →

4,848
pimcorehelmforgeVerified publisher2.0.11 of 6See more

pimcore helmforge 2.0.1

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:12.3.3dd9b303aed4f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

3,216
qdranthelmforgeVerified publisher1.0.51 of 1See more

qdrant helmforge 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.19.112364fe851b9
perl@5.40.1-6
no fix listed

Open the chart page →

836
reactive-resumehelmforgeVerified publisher1.0.02 of 4See more

reactive-resume helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,099
ryothelmforgeVerified publisher1.0.02 of 2See more

ryot helmforge 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

6,093
strapihelmforgeVerified publisher2.3.141 of 3See more

strapi helmforge 2.3.14

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

2,103
supersethelmforgeVerified publisher1.3.63 of 5See more

superset helmforge 1.3.6

3 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/superset:6.1.016b50bbef664
perl@5.36.0-7+deb12u3
no fix listed
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

5,813
text-embeddings-inferencehelmforgeVerified publisher1.0.01 of 2See more

text-embeddings-inference helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,579
tomcathelmforgeVerified publisher1.0.61 of 2See more

tomcat helmforge 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/tomcat:11.0.25-jdk17-temurin-noble9e1d2afa6898
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,301
twentyhelmforgeVerified publisher1.0.12 of 5See more

twenty helmforge 1.0.1

2 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

3,668
wallabaghelmforgeVerified publisher1.3.61 of 3See more

wallabag helmforge 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

2,802
zookeeperhelmforgeVerified publisher1.0.21 of 1See more

zookeeper helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5f258365d4882
perl@5.34.0-3ubuntu1.7
no fix listed

Open the chart page →

3,154
myapphelmingapp0.1.01 of 1See more

myapp helmingapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
muhammedgamal/fp23:latest74b4cd69b6fa
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

12,694
jellyfinhelm-l3st86Verified publisher0.1.81 of 1See more

jellyfin helm-l3st86 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jellyfin/jellyfin:latestaefb67e6a7ff
perl@5.40.1-6
no fix listed

Open the chart page →

2,639
openaevhelm-openbasVerified publisher2.0.53 of 7See more

openaev helm-openbas 2.0.5

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
perl@5.36.0-7+deb12u2
no fix listed
openaev/platform:3.260904.00a12ce8b3db9
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

7,564
openbashelm-openbasVerified publisher1.8.144 of 7See more

openbas helm-openbas 1.8.14

4 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
perl@5.36.0-7+deb12u2
no fix listed
openbas/caldera-server:5.1.0a277796d9724
perl@5.36.0-7+deb12u1
no fix listed
openbas/platform:2.0.5d986d80b0a75
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

25,217
pageshelm-repo1.0.02 of 3See more

pages helm-repo 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,262
steampipehelm-steampipeVerified publisher2.4.11 of 1See more

steampipe helm-steampipe 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,159
svacerhelm-svacer0.6.01 of 1See more

svacer helm-svacer 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ispras/svacer:11-2-042aa9fa9f189
perl@5.34.0-3ubuntu1.4
no fix listed

Open the chart page →

6,105
my-nginxhelmtaiwo0.1.01 of 1See more

my-nginx helmtaiwo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,861
samplehelmapphelmtraining3.0.01 of 1See more

samplehelmapp helmtraining 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
praravind1801/helmimages:3.0.0f29d637b9ce1
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

6,013
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

14,421
hivemq-edgehivemqOfficialVerified publisher0.1.361 of 1See more

hivemq-edge hivemq 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
hivemq/hivemq-edge:2026.14d8250a233cea
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

1,251
printserverhmediadeVerified publisher1.0.22 of 4See more

printserver hmediade 1.0.2

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
hmediade/printserver:latest481a552c8e1c
perl@5.34.0-3ubuntu1.3
no fix listed
hmediade/printserver-init:latest7f005eb6c718
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

11,002
home-ha-mockhome-ha-mockVerified publisher2.0.51 of 1See more

home-ha-mock home-ha-mock 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

3,069
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
perl@5.36.0-7
no fix listed

Open the chart page →

16,444
home-security-demohome-security-demoVerified publisher2.0.121 of 3See more

home-security-demo home-security-demo 2.0.12

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

3,152
paperlesshpVerified publisher0.1.23 of 5See more

paperless hp 0.1.2

3 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/tika:3.3.1.090b7fa1dc018
perl@5.40.1-7build1
no fix listed
gotenberg/gotenberg:8.3467097317623a
perl@5.40.1-6
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
perl@5.40.1-6
no fix listed

Open the chart page →

27,104

Container images carrying it

2,366 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
perl@5.30.0-9ubuntu0.2
no fix listed
1
puppet/puppet-agent:7.14.00b6fd9a6b7da
perl@5.26.1-6ubuntu0.5
no fix listed
1
qdrant/qdrant:v1.7.45f2a56b95266
perl@5.36.0-7+deb12u1
no fix listed
1
qdrant/qdrant:v1.4.166ee661d5241
perl@5.36.0-7
no fix listed
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
perl@5.40.1-6
no fix listed
1
qonstrukt/php:8.4-v8-apache089af7925aa1
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
quickwit/quickwit:v0.8.1d29332bdadcc
perl@5.36.0-7+deb12u1
no fix listed
1
qumine/minecraft-server:v0.1.15c0b650d51132
perl@5.34.0-3ubuntu1.1
no fix listed
1
qxip/qryn:3.2.3977acc9c7a9fd
perl@5.36.0-7+deb12u1
no fix listed
1
rabeh/apibootspring:1.0941007b6946e
perl@5.34.0-3ubuntu1.3
no fix listed
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.4
1
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
perl@5.26.1-6ubuntu0.5
no fix listed
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
perl@5.22.1-9ubuntu0.5
no fix listed
1
razorbladex401/dayz:latest6a4d79248e7d
perl@5.34.0-3ubuntu1.3
no fix listed
1
readysettech/sqp:latest588f3507280e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
readysettech/sqp-duckdb:latest67a83203ce60
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
perl@5.40.1-6
no fix listed
1
redash/redash:25.8.000d813437db5
perl@5.36.0-7+deb12u2
no fix listed
1
redash/redash:26.3.0c5c9148f5c38
perl@5.36.0-7+deb12u3
no fix listed
1
redimp/otterwiki:2778bf30da3da
perl@5.36.0-7+deb12u3
no fix listed
1
redis/redis-stack-server:6.2.6-v251a58f32d412
perl@5.30.0-9ubuntu0.3
no fix listed
1
redis/redis-stack-server:latest798ab84d9f26
perl@5.34.0-3ubuntu1.5
no fix listed
1
redis/redis-stack-server:7.4.0-v0887cf87cc744
perl@5.34.0-3ubuntu1.3
no fix listed
1
redpandadata/redpanda:latest468bd13a9f2b
perl@5.40.1-6
no fix listed
1
resouer/redis-slave:v2e2f198b49ba7
perl@5.18.2-2ubuntu1
no fix listed
1
resurfaceio/resurface:3.7.84d5cda2f64109
perl@5.34.0-3ubuntu1.3
no fix listed
1
rezachalak/bzen-mongo:1.0.034f694325191
perl@5.30.0-9ubuntu0.4
no fix listed
1
rhasspy/wyoming-piper:2.3.169b7f797ae3a
perl@5.36.0-7+deb12u3
no fix listed
1
rhasspy/wyoming-piper:2.5.27d39aafac409
perl@5.40.1-6
no fix listed
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
perl@5.36.0-7+deb12u3
no fix listed
1
rhasspy/wyoming-whisper:3.5.0308b7959a925
perl@5.36.0-7+deb12u3
no fix listed
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
perl@5.30.0-9ubuntu0.2
no fix listed
1
rnwood/smtp4dev:3.6.1912304153668
perl@5.36.0-7+deb12u1
no fix listed
1
robotshop/rs-mongodb:latest119b545823cd
perl@5.30.0-9ubuntu0.2
no fix listed
1
rocketadmin/rocketadmin:1.17.710955ef540b9
perl@5.36.0-7+deb12u3
no fix listed
1
rocketchat/freeswitch:stablecfba5c20a5cc
perl@5.36.0-7+deb12u2
no fix listed
1
rotationalio/endeavor:1.3.0ac566baddc06
perl@5.36.0-7+deb12u3
no fix listed
1
rotationalio/genoa:1.2.03ab583519215
perl@5.36.0-7+deb12u3
no fix listed
1
rotationalio/honu:0.5.069fd30c2e31c
perl@5.36.0-7+deb12u3
no fix listed
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
perl@5.40.1-6
no fix listed
1
rraahul/test:latestbfe2c1183bc0
perl@5.34.0-3ubuntu1.2
no fix listed
1
rrobetti/ojp:0.1.0-beta1141bd88232b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
rspamd/rspamd:4.1.4e870599c970d
perl@5.40.1-6
no fix listed
1
rstmdb/rstmdb:lateste5187f2aaace
perl@5.36.0-7+deb12u3
no fix listed
1
rtuszik/photon-docker:2.4.021549c60f9e6
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
rundeck/rundeck:3.2.74d64fe56f767
perl@5.22.1-9ubuntu0.6
no fix listed
1
rundeck/rundeck:3.0.16b13e8059ad72
perl@5.22.1-9ubuntu0.6
no fix listed
1
ryshe/terraria:latestb1c89f7f359a
perl@5.36.0-7+deb12u3
no fix listed
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
perl@5.34.0-3ubuntu1.3
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.