StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,414
of 17,790 indexed, latest versions
Container images
2,398
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,414 of 17,790 indexed charts deploy, on 2,398 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,377
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,414 by stars
ChartLatestAffected imagesRadar Score
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

18,589
zookeepercloudpirates-zookeeperVerified publisher0.13.111 of 1See more

zookeeper cloudpirates-zookeeper 0.13.11

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5cab8944a33a1
perl@5.34.0-3ubuntu1.8
no fix listed

Open the chart page →

2,966
codefreshcodefresh-onpremOfficialVerified publisher2.12.144 of 42See more

codefresh codefresh-onprem 2.12.14

4 of the 42 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/rabbitmq:4.1.39e635efba431
perl@5.36.0-7+deb12u2
no fix listed
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

15,093
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.38.4447f857a0146
perl@5.34.0-3ubuntu1.8
no fix listed

Open the chart page →

1,524
apim3graviteeioVerified publisher4.12.192 of 4See more

apim3 graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
perl@5.40.1-6
no fix listed
graviteeio/apim-management-api:4.12.19-debian27374522cd04
perl@5.40.1-6
no fix listed

Open the chart page →

4,852
redisgroundhog2k2.4.71 of 1See more

redis groundhog2k 2.4.7

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

978
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
perl@5.40.1-6
no fix listed

Open the chart page →

3,752
memcachedkubelauncherVerified publisher0.1.321 of 1See more

memcached kubelauncher 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/memcacheddigest-pinnedb599ca6b3ff3
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

640
mysqlkubelauncherVerified publisher0.4.41 of 1See more

mysql kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnede9609bd50416
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

982
postgresqlkubelauncherVerified publisher0.4.31 of 1See more

postgresql kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinned1a27e11e5925
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,159
velero-uiotwldVerified publisher0.15.01 of 1See more

velero-ui otwld 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
otwld/velero-ui:0.10.2d1954b759e47
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,354
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2api:3.86f56d239d280
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2auth:3.833ecfda16608
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2notifier:3.8f190a6212195
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2web:3.809989a26c8b7
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

96,933
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
library/kong:3.8.0712e407b20ea
perl@5.34.0-3ubuntu1.7
no fix listed
supabase/edge-runtime:v1.59.0eff9c554d649
perl@5.36.0-7+deb12u1
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
perl@5.36.0-7+deb12u1
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
perl@5.36.0-7+deb12u1
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

23,365
wekanwekanVerified publisher11.83.02 of 3See more

wekan wekan 11.83.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latest6cb94aa01999
perl@5.40.1-6
no fix listed
ghcr.io/wekan/wekan:v11.83137951e3fb40
perl@5.40.1-6+deb13u1
no fix listed

Open the chart page →

1,619
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
perl@5.36.0-7+deb12u1
no fix listed
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

8,586
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,778
budibasebudibase0.0.0-master3 of 7See more

budibase budibase 0.0.0-master

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
perl@5.36.0-7+deb12u3
no fix listed
budibase/proxy:3.41.38d780b6ee602
perl@5.40.1-6
no fix listed
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

10,856
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
perl@5.34.0-3ubuntu1
no fix listed

Open the chart page →

3,496
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,048
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

7,923
cassandrakubelauncherVerified publisher0.1.271 of 1See more

cassandra kubelauncher 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinnedb66aba320083
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,496
etcdkubelauncherVerified publisher0.4.31 of 1See more

etcd kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinned8ab954711fb9
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

818
kafkakubelauncherVerified publisher0.1.261 of 1See more

kafka kubelauncher 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned43e1085cd0a8
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,404
keycloakkubelauncherVerified publisher0.4.41 of 1See more

keycloak kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinnedafe3bd73d7cf
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,296
kubectlkubelauncherVerified publisher0.2.111 of 1See more

kubectl kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned7280594a2f18
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,261
mariadbkubelauncherVerified publisher0.5.71 of 1See more

mariadb kubelauncher 0.5.7

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mariadbdigest-pinnede25056a6ec52
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,107
mongodbkubelauncherVerified publisher0.4.51 of 1See more

mongodb kubelauncher 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinned9bc37ed78a8b
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,386
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

1,284
rabbitmqkubelauncherVerified publisher0.2.111 of 1See more

rabbitmq kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinnedff5a36a457f1
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,124
rediskubelauncherVerified publisher0.5.11 of 1See more

redis kubelauncher 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedbcd8e9a6224f
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

814
zookeeperkubelauncherVerified publisher0.2.111 of 1See more

zookeeper kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/zookeeperdigest-pinned7826e9caa461
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,033
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

3,124
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,503
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,449
zillazillaOfficialVerified publisher2.4.21 of 1See more

zilla zilla 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
perl@5.34.0-3ubuntu1.7
no fix listed

Open the chart page →

1,740
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
perl@5.40.1-6
no fix listed

Open the chart page →

2,962
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

4,284
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,041
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

4,641
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
no fix listed

Open the chart page →

33,180
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

3,675
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

5,403
nextcloudgroundhog2k0.22.61 of 3See more

nextcloud groundhog2k 0.22.6

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nextcloud:34.0.4:34.0.4-apache8418c398d767
perl@5.40.1-6+deb13u1
no fix listed

Open the chart page →

3,837
ilumilumOfficialVerified publisher6.7.34 of 19See more

ilum ilum 6.7.3

4 of the 19 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/postgresql:16233f361c5819
perl@5.36.0-7+deb12u1
no fix listed
ilum/api:6.7.3624fd09528c8
perl@5.40.1-6
no fix listed
ilum/marquez:0.54.06e1d709d41f8
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

23,362
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

3,440
lakekeeperlakekeeperVerified publisher0.12.01 of 2See more

lakekeeper lakekeeper 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
perl@5.40.1-6
no fix listed

Open the chart page →

1,956
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

7,063
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
perl@5.40.1-6
no fix listed

Open the chart page →

5,702
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
perl@5.40.1-6
no fix listed

Open the chart page →

4,354
netris-controllernetrisai2.8.24 of 14See more

netris-controller netrisai 2.8.2

4 of the 14 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
perl@5.30.0-9ubuntu0.5
no fix listed
netrisai/controller-telescope:4.6.0.00414d82948a8b2
perl@5.30.0-9ubuntu0.5
no fix listed
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
perl@5.30.0-9ubuntu0.5
no fix listed
netrisai/controller-web-session-generator:0.2.0a030a31289f4
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

30,504

Container images carrying it

2,398 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
weblate/weblate:2026.9.1.0990720d1737a
perl@5.40.1-7ubuntu0.1
no fix listed
1
wekanteam/wekan:v4.2268a51f0327df
perl@5.30.0-9build1
no fix listed
1
wger/server:2.6997ead43aabd
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
wiktorn/overpass-api:latest9bb5f4a9b54c
perl@5.36.0-7+deb12u3
no fix listed
1
wistefan/mvf:lateste0887302b2d8
perl@5.34.0-3ubuntu1.1
no fix listed
1
wolveix/satisfactory-server:v1.9.1199be1064b18
perl@5.34.0-3ubuntu1.3
no fix listed
1
wolveix/satisfactory-server:v1.9.9464d11e36e10
perl@5.34.0-3ubuntu1.4
no fix listed
1
woojoong/wowza:latestec230db19652
perl@5.26.1-6ubuntu0.2
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
perl@5.34.0-3ubuntu1.3
no fix listed
1
xeladock/mysql_dns:latest4baf531453f1
perl@5.34.0-3ubuntu1
no fix listed
1
xeladock/nginx2:latestc259a67b1dff
perl@5.34.0-3ubuntu1
no fix listed
1
xeotek/kadeck:6.3.439a3b37a17c5
perl@5.34.0-3ubuntu1.5
no fix listed
1
xeotek/kadeck:4.2.94c6b04d9ce55
perl@5.30.0-9ubuntu0.3
no fix listed
1
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
perl@5.22.1-9ubuntu0.9
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
perl@5.36.0-7+deb12u1
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
perl@5.36.0-7+deb12u1
no fix listed
1
yandex/clickhouse-client:21.3863f94a0f607
perl@5.26.1-6ubuntu0.5
no fix listed
1
yandex/clickhouse-server:latest1cbf75aabe1e
perl@5.30.0-9ubuntu0.2
no fix listed
1
yandex/clickhouse-server:21.3.204eccfffb01d7
perl@5.30.0-9ubuntu0.2
no fix listed
1
yandex/clickhouse-server:19.17ab1738a64b70
perl@5.26.1-6ubuntu0.3
no fix listed
1
yandex/clickhouse-server:19.14ccf9c2b5e3f2
perl@5.26.1-6ubuntu0.3
no fix listed
1
yandex/clickhouse-server:19.16d210dc69321e
perl@5.26.1-6ubuntu0.3
no fix listed
1
ybucci/traefik-external-dns-controller:2.2.08d27ad8b5f73
perl@5.40.1-6
no fix listed
1
yetiplatform/yeti:2.9.09bcbe2650a14
perl@5.40.1-6
no fix listed
1
yetiplatform/yeti:latest9c3006cedcca
perl@5.40.1-6
no fix listed
1
yetiplatform/yeti-frontend:latest709064278c7e
perl@5.40.1-6
no fix listed
1
yetiplatform/yeti-frontend:2.9.0873ef15d267b
perl@5.40.1-6
no fix listed
1
youkadev/api-snap:0.1.14db0f9428e67
perl@5.36.0-7+deb12u1
no fix listed
1
youssef11gaber10/flask-service:latest9c727fcfde76
perl@5.40.1-6
no fix listed
1
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
perl@5.30.0-9ubuntu0.2
no fix listed
1
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
perl@5.34.0-3ubuntu1
no fix listed
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
perl@5.30.0-9ubuntu0.2
no fix listed
1
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
perl@5.34.0-3ubuntu1
no fix listed
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
perl@5.30.0-9ubuntu0.2
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
perl@5.34.0-3ubuntu1
no fix listed
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
perl@5.34.0-3ubuntu1
no fix listed
1
zenmldocker/zenml-server:0.96.409027a6312ee
perl@5.36.0-7+deb12u3
no fix listed
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
perl@5.36.0-7+deb12u2
no fix listed
1
zer0tonin/mikochi:1.11.009872bae1554
perl@5.40.1-7ubuntu0.1
no fix listed
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
perl@5.34.0-3ubuntu1.7
no fix listed
1
gcr.io/abacus-labs-dev/hyperlane-agent:10c0ab1-20231215-220639f33e88324a40
perl@5.34.0-3ubuntu1.3
no fix listed
1
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
gcr.io/datadoghq/observability-pipelines-worker:2.21.1de6ff0f1a854
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.