StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,411
of 17,803 indexed, latest versions
Container images
2,391
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,411 of 17,803 indexed charts deploy, on 2,391 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,370
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,411 by stars
ChartLatestAffected imagesRadar Score
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,418
vehicle-dashboardtest-vehi-dash0.1.03 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
perl@5.34.0-3ubuntu1.2
no fix listed
library/mongo:5.0.217c81758cb295
perl@5.30.0-9ubuntu0.4
no fix listed
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

20,436
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,017
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

10,186
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

10,115
the0the0Verified publisher0.9.82 of 9See more

the0 the0 0.9.8

2 of the 9 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:7-jammy406a4fdca9fc
perl@5.34.0-3ubuntu1.7
no fix listed
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

7,503
standard-applicationthebitgram1.0.121 of 1See more

standard-application thebitgram 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
perl@5.22.1-9
no fix listed

Open the chart page →

11,028
trafficlight-apithecampagnards0.1.11 of 1See more

trafficlight-api thecampagnards 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
thecampagnards/trafficlight-api:main7dca9d973837
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,411
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

25,531
pagesthiru-pages1.0.02 of 3See more

pages thiru-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,261
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,261
voyagertibuntu1.2.01 of 1See more

voyager tibuntu 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/aeharding/voyager:latest779759172676
perl@5.40.1-6
no fix listed

Open the chart page →

1,879
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
perl@5.40.1-6
no fix listed

Open the chart page →

4,464
joplintobiassackmann0.1.72 of 2See more

joplin tobiassackmann 0.1.7

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
no fix listed
joplin/server:latest3f7b852959aa
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,650
todoapitodoapi-appVerified publisher0.1.01 of 2See more

todoapi todoapi-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

6,861
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
perl@5.40.1-6
no fix listed

Open the chart page →

7,076
test0tohlejezkouska0.1.01 of 2See more

test0 tohlejezkouska 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

3,348
netbirdtotmicro1.8.21 of 4See more

netbird totmicro 1.8.2

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
netbirdio/management:0.60.252682e5f48f9
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

6,064
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
perl@0:1.28-419.el8_4.1
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb

Open the chart page →

12,726
traefik-external-dns-controllertraefik-external-dns-operator2.2.01 of 1See more

traefik-external-dns-controller traefik-external-dns-operator 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
perl@5.40.1-6
no fix listed

Open the chart page →

1,525
apptreenityVerified publisher0.1.531 of 2See more

app treenity 0.1.53

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
perl@5.40.1-6
no fix listed

Open the chart page →

1,854
treenitytreenityVerified publisher0.1.31 of 4See more

treenity treenity 0.1.3

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
perl@5.40.1-6
no fix listed

Open the chart page →

3,402
orchestra-login-portaltremolo2.3.981 of 1See more

orchestra-login-portal tremolo 2.3.98

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

3,019
saleor-appstrieb-work0.6.01 of 5See more

saleor-apps trieb-work 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:8.2.2f0957bcaa75f
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,487
trowtrow0.13.01 of 1See more

trow trow 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
perl@5.40.1-6
no fix listed

Open the chart page →

1,317
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

17,427
altinnendata-apptumogroup0.1.171 of 1See more

altinnendata-app tumogroup 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sondresjo/altinnendata-app:v1.9.1c2707839d8a3
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

1,883
bobby-apitumogroup1.0.11 of 1See more

bobby-api tumogroup 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sondresjo/bobby-api:latestfe534731909a
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

2,343
nstuning-apptumogroup0.1.181 of 1See more

nstuning-app tumogroup 0.1.18

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sondresjo/nstuning-app:v1.6.113a6795bf36da
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

1,883
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.2.0-v10e44b2b49d059
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

5,634
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

4,139
umbrella-chartumbrella-chartVerified publisher0.1.13 of 5See more

umbrella-chart umbrella-chart 0.1.1

3 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
hassroutyyoussef/accountservice:latest1f01edf1ee0c
perl@5.36.0-7+deb12u1
no fix listed
hassroutyyoussef/orderservice:latest2fc3d1617928
perl@5.36.0-7+deb12u1
no fix listed
hassroutyyoussef/userservice:lateste0392e2b4a90
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

7,590
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

8,694
applicationuniversal-helm-chartVerified publisher0.4.31 of 1See more

application universal-helm-chart 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,879
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,282
opencloudunxwaresVerified publisher0.2.37 of 13See more

opencloud unxwares 0.2.3

7 of the 13 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
perl@5.36.0-7+deb12u1
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
perl@5.36.0-7+deb12u1
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
perl@5.36.0-7+deb12u1
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
perl@5.36.0-7+deb12u1
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
perl@5.36.0-7+deb12u1
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

45,468
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

15,488
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
perl@5.36.0-7
no fix listed

Open the chart page →

14,468
telegram-rebotvcnngrVerified publisher1.0.02 of 3See more

telegram-rebot vcnngr 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vcnngr/telegram-login:latest1a849a997b6d
perl@5.36.0-7+deb12u2
no fix listed
vcnngr/telegram-rebot:latest30f1f05e57a6
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

5,112
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,434
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
perl@5.30.0-9ubuntu0.4
no fix listed
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

150,073
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

72,549
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

10,859
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,342
bugsinkvictorlane0.3.72 of 2See more

bugsink victorlane 0.3.7

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bugsink/bugsink:2ecdd84587746
perl@5.40.1-6
no fix listed
library/mariadb:12.0-noble607835cd628b
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,169
twenty-crmvictorlane0.0.12 of 3See more

twenty-crm victorlane 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
redis/redis-stack-server:latest798ab84d9f26
perl@5.34.0-3ubuntu1.5
no fix listed
twentycrm/twenty-postgres-spilo:latest2f78405a78be
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

64,741
pagesvictor-pages1.0.02 of 3See more

pages victor-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,261
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
perl@5.40.1-6
no fix listed

Open the chart page →

2,015
kube-monitoring-telegram-botviento-repository1.0.01 of 1See more

kube-monitoring-telegram-bot viento-repository 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

7,896
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

7,741

Container images carrying it

2,391 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
perl@5.40.1-6
no fix listed
1
rraahul/test:latestbfe2c1183bc0
perl@5.34.0-3ubuntu1.2
no fix listed
1
rrobetti/ojp:0.1.0-beta1141bd88232b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
rspamd/rspamd:4.1.4e870599c970d
perl@5.40.1-6
no fix listed
1
rstmdb/rstmdb:lateste5187f2aaace
perl@5.36.0-7+deb12u3
no fix listed
1
rtuszik/photon-docker:2.4.021549c60f9e6
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
rundeck/rundeck:3.2.74d64fe56f767
perl@5.22.1-9ubuntu0.6
no fix listed
1
rundeck/rundeck:3.0.16b13e8059ad72
perl@5.22.1-9ubuntu0.6
no fix listed
1
ryshe/terraria:latestb1c89f7f359a
perl@5.36.0-7+deb12u3
no fix listed
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
perl@5.34.0-3ubuntu1.3
no fix listed
1
ryuunosukeds3/orbital:latest0879f7261b10
perl@5.36.0-7+deb12u2
no fix listed
1
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3ce9ce8293e4e
perl@5.34.0-3ubuntu1.2
no fix listed
1
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9bb64bf14467d
perl@5.34.0-3ubuntu1.2
no fix listed
1
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525799c35f9f306
perl@5.34.0-3ubuntu1.2
no fix listed
1
santisbon/evwatcher:latestc4e994ca4540
perl@5.36.0-7
no fix listed
1
santisbon/evworker:lateste807283f8d69
perl@5.36.0-7
no fix listed
1
santisbon/speedtest:latest8ee3a1697227
perl@5.36.0-7
no fix listed
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
perl@5.36.0-7+deb12u1
no fix listed
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
perl@5.36.0-7
no fix listed
1
schemahero/schemahero-manager:0.22.11609e1a05cd3
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
perl@5.34.0-3ubuntu1.3
no fix listed
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
perl@5.34.0-3ubuntu1.3
no fix listed
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
perl@5.34.0-3ubuntu1.3
no fix listed
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
perl@5.40.1-7ubuntu0.1
no fix listed
1
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
perl@5.40.1-7ubuntu0.1
no fix listed
1
scrapinghub/splash:3.4.1a5f89bc84606
perl@5.26.1-6ubuntu0.3
no fix listed
1
scsibug/nostr-rs-relay:0.9.003f54bfbffff
perl@5.36.0-7
no fix listed
1
seafileltd/seafile-mc:9.0.106693911bcc40
perl@5.30.0-9ubuntu0.3
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
perl@5.30.0-9ubuntu0.4
no fix listed
1
seafileltd/seafile-mc:9.0.97ac833196f60
perl@5.30.0-9ubuntu0.2
no fix listed
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
perl@5.34.0-3ubuntu1.3
no fix listed
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
perl@5.30.0-9ubuntu0.2
no fix listed
1
sebt3/kuberest:1.4.00ccce5d6d4d2
perl@5.36.0-7+deb12u3
no fix listed
1
seldonio/locust-core:0.81d0da98a2d76
perl@5.22.1-9ubuntu0.6
no fix listed
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
perl@0:1.28-419.el8_4.1
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-Thread-Queue@3.13-1.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
0:3.14-457.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb
1
seoulorigin/janus-ml-sidecar:v3.192cbaad0c540
perl@5.40.1-6
no fix listed
1
sepehrmdn/mirasys-assignment:1.0.12567228e33c8
perl@5.36.0-7+deb12u3
no fix listed
1
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
perl@5.40.1-6
no fix listed
1
shamimkuet/nginx:1.0.2b82902a76a04
perl@5.36.0-7+deb12u1
no fix listed
1
shaowenchen/ops-controller-manager:latest26da43bb5b66
perl@5.34.0-3ubuntu1.7
no fix listed
1
shaowenchen/ops-server:latest315444f703f4
perl@5.34.0-3ubuntu1.5
no fix listed
1
sharanalwar/redchef-backend:latest8d3cab80df49
perl@5.36.0-7+deb12u1
no fix listed
1
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
perl@5.26.1-6ubuntu0.5
no fix listed
1
shwcloud/seawise-backup:v1.7.1a97479a54df4
perl@5.40.1-6
no fix listed
1
sifrai/grandine:unstable59ef4c0d4d7f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
signalen/backend:2.50.14760256000738
perl@5.36.0-7+deb12u3
no fix listed
1
signoz/signoz-otel-collector:v0.144.1034ecb436b687
perl@5.36.0-7+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.