StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,414
of 17,790 indexed, latest versions
Container images
2,398
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,414 of 17,790 indexed charts deploy, on 2,398 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,377
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,414 by stars
ChartLatestAffected imagesRadar Score
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
perl@5.40.1-6
no fix listed

Open the chart page →

2,267
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

17,370
paperless-ngxpaperless-ngxVerified publisher0.3.223 of 3See more

paperless-ngx paperless-ngx 0.3.22

3 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
no fix listed
valkey/valkey:9.1.2c123e3715db6
perl@5.40.1-6
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
perl@5.40.1-6
no fix listed

Open the chart page →

8,553
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
perl@5.26.1-6ubuntu0.5
no fix listed
platform9community/api-gateway:latest40a4970de568
perl@5.26.1-6ubuntu0.5
no fix listed
platform9community/customers-service:latest2089811e5cc6
perl@5.26.1-6ubuntu0.5
no fix listed
platform9community/vets-service:latestd1165c94dfb3
perl@5.26.1-6ubuntu0.5
no fix listed
platform9community/visits-service:latest8d11b50368c6
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

41,926
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
perl@5.34.0-3ubuntu1.3
no fix listed
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

14,281
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,827
tbmq-clustertbmq-helm-chartOfficialVerified publisher2.1.02 of 3See more

tbmq-cluster tbmq-helm-chart 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
perl@5.40.1-6
no fix listed
thingsboard/tbmq-node:2.4.070661025dba5
perl@5.40.1-6
no fix listed

Open the chart page →

3,575
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

7,360
plexutkuozdemirVerified publisher2.1.11 of 1See more

plex utkuozdemir 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
linuxserver/plex:1.25.24a13ced2326c
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

6,390
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,327
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
perl@5.34.0-3ubuntu1.2
no fix listed

Open the chart page →

5,679
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
perl@5.30.0-9ubuntu0.2
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
perl@5.30.0-9ubuntu0.2
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

30,813
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
perl@5.40.1-6
no fix listed

Open the chart page →

2,650
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

6,531
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

12,166
memcachedcloudpirates-memcachedVerified publisher0.14.91 of 1See more

memcached cloudpirates-memcached 0.14.9

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
perl@5.40.1-6
no fix listed

Open the chart page →

1,074
cluster-secretclutersecretVerified publisher0.7.01 of 1See more

cluster-secret clutersecret 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,050
codercoderOfficialVerified publisher1.44.61 of 2See more

coder coder 1.44.6

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
coderenvs/timescale:1.44.676fd37fe6830
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-2.el8_9.1
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

7,183
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

5,943
cortexcortex3.3.82 of 4See more

cortex cortex 3.3.8

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
perl@5.40.1-6
no fix listed
library/nginx:1.3105b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

3,948
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,544
valkeygroundhog2k2.3.41 of 1See more

valkey groundhog2k 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2475ee65cc75c
perl@5.40.1-6
no fix listed

Open the chart page →

829
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
perl@5.34.0-3ubuntu1.2
no fix listed

Open the chart page →

4,954
docmosthelmforgeVerified publisher1.2.123 of 4See more

docmost helmforge 1.2.12

3 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
docmost/docmost:0.96.0b56947fcfd08
perl@5.40.1-6
no fix listed
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed
library/redis:8.10.1298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

4,113
wordpresshelmforgeVerified publisher3.0.61 of 3See more

wordpress helmforge 3.0.6

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
perl@5.40.1-6
no fix listed

Open the chart page →

4,215
coturnjaconiVerified publisher1.0.51 of 1See more

coturn jaconi 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
coturn/coturn:4.10.0-r1f4c2af06c3c5
perl@5.40.1-6
no fix listed

Open the chart page →

2,924
mongooseimmongoose0.4.111 of 1See more

mongooseim mongoose 0.4.11

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
erlangsolutions/mongooseim:6.6.0cc5bf032931f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

1,307
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

8,692
nginx-ingressnginx-ingress-chartVerified publisher0.0.0-edge1 of 1See more

nginx-ingress nginx-ingress-chart 0.0.0-edge

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
nginx/nginx-ingress:edge520d439f9a9a
perl@5.40.1-6
no fix listed

Open the chart page →

1,266
technitium-dnsserverobeoneVerified publisher1.13.01 of 1See more

technitium-dnsserver obeone 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
technitium/dns-server:15.4.0df7d90ef0f7b
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

1,231
passboltpassbolt2.1.16 of 6See more

passbolt passbolt 2.1.1

6 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/redis-sentinel:8.2.1-debian-12-r00ca3ea1d2f82
perl@5.36.0-7+deb12u2
no fix listed
library/haproxy:3.4.10f597665a2a6
perl@5.40.1-6
no fix listed
library/mariadb:latestdd9b303aed4f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
perl@5.40.1-6
no fix listed

Open the chart page →

13,523
reposilitereposilite1.4.21 of 1See more

reposilite reposilite 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.6.390de4c8e6c0e
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

1,033
mssqlserver-2022simcube1.2.31 of 1See more

mssqlserver-2022 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
perl@5.34.0-3ubuntu1.7
no fix listed

Open the chart page →

2,955
swo-k8s-collectorsolarwindsOfficialVerified publisher5.3.01 of 3See more

swo-k8s-collector solarwinds 5.3.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,377
thehivestrangebee-helmOfficialVerified publisher1.0.74 of 7See more

thehive strangebee-helm 1.0.7

4 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
perl@5.36.0-7+deb12u2
no fix listed
strangebee/thehive:5.8.0-1a7f7b05fba24
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

16,220
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

14,327
minecraft-overvieweralphani-helm-chartsVerified publisher0.1.01 of 3See more

minecraft-overviewer alphani-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
no fix listed

Open the chart page →

3,402
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

8,923
openvpn-asas-helm-chartOfficialVerified publisher0.2.11 of 1See more

openvpn-as as-helm-chart 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
openvpn/openvpn-as:latest2253c10ec652
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,722
baserowbaserow-chartVerified publisher1.0.565 of 6See more

baserow baserow-chart 1.0.56

5 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
baserow/backend:2.3.37c00549b3a6f
perl@5.40.1-6
no fix listed
baserow/web-frontend:2.3.3566d24c7d9f5
perl@5.40.1-6
no fix listed
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/redis:7.2.5-debian-12-r05261cae9e407
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

17,413
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
perl@5.30.0-9ubuntu0.2
no fix listed
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

53,052
headwind-mdmchristianhuthVerified publisher5.10.22 of 2See more

headwind-mdm christianhuth 5.10.2

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
no fix listed
headwindmdm/hmdm:0.1.93550b4840840
perl@5.34.0-3ubuntu1.7
no fix listed

Open the chart page →

5,929
dolibarrcowboysysopVerified publisher9.0.32 of 3See more

dolibarr cowboysysop 9.0.3

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
perl@5.36.0-7+deb12u1
no fix listed
dolibarr/dolibarr:22.0.47ad88fc9b13c
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,208
dagster-user-deploymentsdagsterVerified publisher1.13.221 of 1See more

dagster-user-deployments dagster 1.13.22

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dagster/user-code-example:1.13.225947f9ae481c
perl@5.40.1-6
no fix listed

Open the chart page →

955
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

14,151
seafiledatamateVerified publisher0.6.04 of 6See more

seafile datamate 0.6.0

4 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/memcached:1.6.29-debian-12-r4ff0e7239c17c
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
perl@5.36.0-7+deb12u1
no fix listed
datamate/seafile-professional:11.0.202dd66b722464
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

27,426
dialdialOfficialVerified publisher7.2.01 of 4See more

dial dial 7.2.0

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
perl@5.40.1-6
no fix listed

Open the chart page →

2,186
jellyfindjjudas21Verified publisher4.0.81 of 1See more

jellyfin djjudas21 4.0.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
perl@5.40.1-6
no fix listed

Open the chart page →

2,626
plexgabe565Verified publisher0.5.11 of 1See more

plex gabe565 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.4

Open the chart page →

2,583
geonode-k8sgeonode-k8sVerified publisher2.0.04 of 10See more

geonode-k8s geonode-k8s 2.0.0

4 of the 10 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
perl@5.34.0-3ubuntu1.5
no fix listed
geopython/pycsw:3.0.0-beta284662ea6b78b
perl@5.36.0-7+deb12u3
no fix listed
library/memcached:1.6.40cc523a19da58
perl@5.40.1-6
no fix listed
library/redis:8.4.03906b477e4b6
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

14,112

Container images carrying it

2,398 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/glassflow/glassflow-notifier:v1.0.3d1b0ce10b513
perl@5.40.1-6
no fix listed
1
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
perl@5.40.1-6
no fix listed
1
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
perl@5.40.1-6
no fix listed
1
ghcr.io/goauthentik/server:2026.8.2ff8489a5af4f
perl@5.40.1-6
no fix listed
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/grycap/im:latest06a16d4f279f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
perl@5.40.1-6
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/hypolia/kanri:0.1.2-rc4fa7d5cc7fb7d
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/icegatetech/icegate-ingest:0.1.1bae3c441894a
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/icegatetech/icegate-maintain:0.1.193e85b2b76ee
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/icegatetech/icegate-query:0.1.17542b4e7fff2
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/icoretech/codex-pooler:0.7.81bebc7e4a770
perl@5.40.1-6
no fix listed
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
perl@5.36.0-7+deb12u2
no fix listed
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/iisas/domino-rest:latest3009350bfc11
perl@5.40.1-6
no fix listed
1
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/immich-app/immich-server:v3.2.12ab6a6273755
perl@5.40.1-6
no fix listed
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
perl@5.40.1-6
no fix listed
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
perl@5.40.1-6
no fix listed
1
ghcr.io/interlink-hq/interlink/virtual-kubelet-inttw:latest0e05a7b49c33
perl@5.34.0-3ubuntu1.7
no fix listed
1
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
perl@5.34.0-3ubuntu1.4
no fix listed
1
ghcr.io/itobey/playlist-mirror:1.0.0601082677a46
perl@5.40.1-6
no fix listed
1
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
perl@5.36.0-7+deb12u2
no fix listed
1
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
perl@5.40.1-6
no fix listed
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
perl@5.26.1-6ubuntu0.7
no fix listed
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
perl@5.34.0-3ubuntu1
no fix listed
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
perl@5.30.0-9ubuntu0.2
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.