StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,414
of 17,790 indexed, latest versions
Container images
2,398
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,414 of 17,790 indexed charts deploy, on 2,398 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,377
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,414 by stars
ChartLatestAffected imagesRadar Score
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,753
kuma-ingress-watcherkuma-ingress-watcherVerified publisher1.4.01 of 1See more

kuma-ingress-watcher kuma-ingress-watcher 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,679
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

12,473
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

114,050
ohifkylesferrazzaVerified publisher0.1.01 of 2See more

ohif kylesferrazza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jodogne/orthanc-plugins:latest6ff510aa29c2
perl@5.40.1-6
no fix listed

Open the chart page →

3,534
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,571
api-gatewaylabs64io-helm-chartsVerified publisher0.12.01 of 1See more

api-gateway labs64io-helm-charts 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
labs64/traefik-authproxy:0.0.3dfc6086dfbce
perl@5.40.1-6
no fix listed

Open the chart page →

1,029
auditflowlabs64io-helm-chartsVerified publisher0.12.11 of 3See more

auditflow labs64io-helm-charts 0.12.1

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinnedc7b26d3ca11c
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,492
checkoutlabs64io-helm-chartsVerified publisher0.8.01 of 3See more

checkout labs64io-helm-charts 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

1,649
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.02 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
labs64/payment-gateway:0.0.10c66feefca17
perl@5.40.1-7ubuntu0.1
no fix listed
library/postgres:184ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

2,725
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,031
lgtm-stacklgtm-stackVerified publisher0.1.31 of 8See more

lgtm-stack lgtm-stack 0.1.3

1 of the 8 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.10f4434c92b3e
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

5,667
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

35,092
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,459
halitesql0.1.51 of 2See more

ha litesql 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/litesql/ha:latest4029479b8ea7
perl@5.40.1-6
no fix listed

Open the chart page →

1,128
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

7,923
clickhouseliwenhe1.0.11 of 3See more

clickhouse liwenhe 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.14ccf9c2b5e3f2
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

6,769
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,252
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,774
plexluiscajl1.0.11 of 2See more

plex luiscajl 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

854
voice-biometricslumenvox2.0.112 of 26See more

voice-biometrics lumenvox 2.0.1

12 of the 26 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-assure-identity:2.0.0147854a3c916
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-audit:2.0.079428add7f38
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-binary-storage:2.0.053decadc102d
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-deployment:2.0.0ea8110886d38
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-management-api:2.0.0b9a23345eabd
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-reporting:2.0.07a9ffdc2178a
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-voice-verifier:2.0.014170ad34903
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

71,268
actualbudgetm0nsterrr-actualbudgetVerified publisher2.10.01 of 1See more

actualbudget m0nsterrr-actualbudget 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,112
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

6,416
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,752
redismagefleet-redis0.1.01 of 1See more

redis magefleet-redis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:7.274566c6910d1
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,072
magentomagento3.2.33 of 12See more

magento magento 3.2.3

3 of the 12 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
perl@5.30.0-9ubuntu0.5
no fix listed
library/rabbitmq:4.1.0-management935b3f84c1e4
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
library/redis:7.274566c6910d1
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

13,643
maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,017
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

19,195
mcpmcp-chartsVerified publisher0.0.233 of 7See more

mcp mcp-charts 0.0.23

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
perl@5.40.1-6
no fix listed
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
perl@5.40.1-6
no fix listed
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

7,025
jellyfinmedia-servarrVerified publisher0.16.01 of 2See more

jellyfin media-servarr 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
perl@5.40.1-6
no fix listed

Open the chart page →

2,775
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,197
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
perl@5.40.1-6build1
no fix listed

Open the chart page →

11,109
model-manager-loadermodel-manager-loader1.27.01 of 1See more

model-manager-loader model-manager-loader 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
perl@5.40.1-6
no fix listed

Open the chart page →

2,710
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

13,812
redminemt1905027.3.42 of 3See more

redmine mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
perl@5.40.1-6
no fix listed
library/redmine:6.1.204ac44a2595b
perl@5.40.1-6
no fix listed

Open the chart page →

7,583
12factormyaVerified publisher24.1.21 of 1See more

12factor mya 24.1.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
my-react-appmy-react-app0.1.51 of 1See more

my-react-app my-react-app 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
n3uronn3uronVerified publisher0.3.51 of 1See more

n3uron n3uron 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
n3uronhub/n3uron:v1.22.4423a0bdd9cb9
perl@5.40.1-6
no fix listed

Open the chart page →

1,907
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

3,732
spring-helmnaveenalla-springboot1.0.01 of 2See more

spring-helm naveenalla-springboot 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

1,649
clowder2ncsaVerified publisher1.9.75 of 12See more

clowder2 ncsa 1.9.7

5 of the 12 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
perl@5.36.0-7+deb12u1
no fix listed
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
perl@5.36.0-7+deb12u3
no fix listed
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
perl@5.36.0-7+deb12u3
no fix listed
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

37,504
nginx-chartnginx-chart-testVerified publisher0.1.11 of 1See more

nginx-chart nginx-chart-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
helm-composenousefreakVerified publisher0.1.32 of 2See more

helm-compose nousefreak 0.1.3

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:10.8.2-focal490f01279be1
perl@5.30.0-9ubuntu0.2
no fix listed
library/wordpress:latest5a93c470ae82
perl@5.40.1-6
no fix listed

Open the chart page →

14,363
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,062
onechartonechart-slVerified publisher0.76.01 of 1See more

onechart onechart-sl 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
perl@5.36.0-7
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

14,884
dhcp-serveropencord1.0.21 of 1See more

dhcp-server opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
networkboot/dhcpd:lateste99bbfbd6fb2
perl@5.34.0-3ubuntu1
no fix listed

Open the chart page →

4,208
librechatopenshift1.9.02 of 3See more

librechat openshift 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,849
opentelemetry-demoopentelemetry-helmVerified publisher0.41.27 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.2

7 of the 34 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
perl@5.40.1-6
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-frontend-proxy1c53bfb59697
perl@5.34.0-3ubuntu1.7
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-mcp654f860148ba
perl@5.40.1-6
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
perl@5.40.1-6
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-accounting74c490f862da
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/open-telemetry/demo:3.0.0-agentdf5ee05e23e3
perl@5.40.1-6
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

22,916
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

6,936

Container images carrying it

2,398 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
trueosiris/vrising:latest9356f98ad561
perl@5.34.0-3ubuntu1.5
no fix listed
1
tussanakorndev/kube-pod-alerts:1.0.5216fdadadf9a
perl@5.40.1-6
no fix listed
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
perl@5.34.0-3ubuntu1.3
no fix listed
1
typesense/typesense:0.25.1035ccfbc3fd8
perl@5.34.0-3ubuntu1.2
no fix listed
1
typesense/typesense:0.23.03accb727cbe2
perl@5.22.1-9ubuntu0.9
no fix listed
1
typesense/typesense:30.191604dc128e2
perl@5.34.0-3ubuntu1.5
no fix listed
1
typesense/typesense:28.0.rc35dea1b62b7b6e
perl@5.34.0-3ubuntu1.3
no fix listed
1
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
perl@5.30.0-9ubuntu0.5
no fix listed
1
ubuntu/squid:5.2-22.04_beta723891b5bc74
perl@5.34.0-3ubuntu1.5
no fix listed
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
perl@5.36.0-7+deb12u2
no fix listed
1
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
perl@5.30.0-9ubuntu0.2
no fix listed
1
v3xl/kubesend:0.1.06f62ca96be82
perl@5.36.0-7+deb12u2
no fix listed
1
valkey/valkey:8.1.61f84517eca8e
perl@5.40.1-6
no fix listed
1
valkey/valkey:9.0.54c64dfeae602
perl@5.40.1-6
no fix listed
1
valkey/valkey:8.0.1c5d4f082b76d
perl@5.36.0-7+deb12u1
no fix listed
1
vaultwarden/server:1.35.443498a94b22f
perl@5.40.1-6
no fix listed
1
vaultwarden/server:1.34.384fd8a47f58d
perl@5.36.0-7+deb12u2
no fix listed
1
vaultwarden/server:1.35.79a8eec71f4a5
perl@5.40.1-6
no fix listed
1
vcnngr/telegram-login:latest1a849a997b6d
perl@5.36.0-7+deb12u2
no fix listed
1
vcnngr/telegram-rebot:latest30f1f05e57a6
perl@5.36.0-7+deb12u2
no fix listed
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
perl@5.36.0-7+deb12u2
no fix listed
1
venturenox/redis:latest83b471c193ba
perl@5.36.0-7+deb12u1
no fix listed
1
vexorian/dizquetv:1.4.37e2b99844a5c
perl@5.26.1-6ubuntu0.5
no fix listed
1
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
perl@5.26.1-6ubuntu0.5
no fix listed
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
perl@5.26.1-6ubuntu0.6
no fix listed
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
perl@0:1.28-420.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
perl@5.36.0-7+deb12u1
no fix listed
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-2.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb
1
vlebediantsev/notes-admin-front:latest007c6670ff48
perl@5.36.0-7
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
perl@5.36.0-7
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
perl@5.36.0-7
no fix listed
1
voltha/bbsim:1.16.7d90403d58016
perl@5.26.1-6ubuntu0.7
no fix listed
1
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
perl@5.26.1-6ubuntu0.7
no fix listed
1
voltha/bbsim-sadis-server:0.4.0762b272d439e
perl@5.26.1-6ubuntu0.7
no fix listed
1
voltha/voltha-cli:1.6.0c4e41e92f046
perl@5.22.1-9ubuntu0.5
no fix listed
1
voltha/voltha-envoy:1.6.059ab2a00f712
perl@5.18.2-2ubuntu1.1
no fix listed
1
voltha/voltha-netconf:1.6.037f80524c207
perl@5.22.1-9ubuntu0.5
no fix listed
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
perl@5.22.1-9ubuntu0.5
no fix listed
1
voltha/voltha-onos:5.1.8e038acb950d3
perl@5.26.1-6ubuntu0.3
no fix listed
1
voltha/voltha-tester:1.7.0655c3048a602
perl@5.22.1-9ubuntu0.6
no fix listed
1
voltha/voltha-voltha:1.6.0ff596b62de59
perl@5.22.1-9ubuntu0.5
no fix listed
1
wallarm/aih-scanner:2.7.11f1cb26db1f5b
perl@5.40.1-6
no fix listed
1
wallarm/api-gateway:0.2.0a3d4d2f780e8
perl@5.36.0-7+deb12u3
no fix listed
1
wallarm/gateway-controller:0.4.09c6ed23e2f0e
perl@5.40.1-6
no fix listed
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
perl@5.30.0-9ubuntu0.3
no fix listed
1
wasmcloud/wasmcloud:0.81.05c7acfe7e8e1
perl@5.36.0-7
no fix listed
1
wateim/lighthouse-launch:latest2520149ee574
perl@5.34.0-3ubuntu1.3
no fix listed
1
wavefronthq/proxy:9.2d1064d28f6eb
perl@5.26.1-6ubuntu0.3
no fix listed
1
wazuh/wazuh-dashboard:4.4.11787550d2358
perl@5.30.0-9ubuntu0.3
no fix listed
1
wazuh/wazuh-manager:4.4.121994f40e0da
perl@5.30.0-9ubuntu0.3
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.