StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,411
of 17,803 indexed, latest versions
Container images
2,391
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,411 of 17,803 indexed charts deploy, on 2,391 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,370
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,411 by stars
ChartLatestAffected imagesRadar Score
satisfactoryschichtelVerified publisher0.3.31 of 1See more

satisfactory schichtel 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.9464d11e36e10
perl@5.34.0-3ubuntu1.4
no fix listed

Open the chart page →

3,578
vaultwardenschichtelVerified publisher0.9.21 of 1See more

vaultwarden schichtel 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
perl@5.40.1-6
no fix listed

Open the chart page →

1,785
wordpressschichtelVerified publisher0.10.102 of 2See more

wordpress schichtel 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/wordpress:6.9.4-fpmad4a8bae2eb4
perl@5.40.1-6
no fix listed
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
perl@5.40.1-6
no fix listed

Open the chart page →

8,354
otterwikischmitzis0.1.01 of 1See more

otterwiki schmitzis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
redimp/otterwiki:2778bf30da3da
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,286
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

58,090
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
typesense/typesense:0.25.1035ccfbc3fd8
perl@5.34.0-3ubuntu1.2
no fix listed

Open the chart page →

4,124
jellyfinschoolguys-helmcharts0.4.21 of 1See more

jellyfin schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.81694ff069f0c
perl@5.40.1-6
no fix listed

Open the chart page →

3,054
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
perl@5.40.1-7build1
no fix listed

Open the chart page →

47,649
satisfactory-serverschoolguys-helmcharts0.1.81 of 1See more

satisfactory-server schoolguys-helmcharts 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

3,480
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,950
unboundschoolguys-helmcharts0.1.11 of 1See more

unbound schoolguys-helmcharts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
mvance/unbound:1.20.04bf67b567f39
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,154
wyoming-faster-whisperschoolguys-helmcharts0.1.41 of 1See more

wyoming-faster-whisper schoolguys-helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rhasspy/wyoming-whisper:3.5.0308b7959a925
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,318
wyoming-piperschoolguys-helmcharts0.1.41 of 1See more

wyoming-piper schoolguys-helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rhasspy/wyoming-piper:2.3.169b7f797ae3a
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,891
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,747
search-proxysearch-proxy2026.38.01 of 1See more

search-proxy search-proxy 2026.38.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
perl@5.40.1-6
no fix listed

Open the chart page →

1,323
seawise-dashboardseawiseVerified publisher1.7.11 of 1See more

seawise-dashboard seawise 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
shwcloud/seawise-backup:v1.7.1a97479a54df4
perl@5.40.1-6
no fix listed

Open the chart page →

1,129
pagessekharpkube1.0.02 of 3See more

pages sekharpkube 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,261
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

75,872
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
perl@0:1.28-419.el8_4.1
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-Thread-Queue@3.13-1.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
0:3.14-457.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

22,351
postgresself-hosters-by-nightVerified publisher0.14.31 of 1See more

postgres self-hosters-by-night 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
perl@5.40.1-6
no fix listed

Open the chart page →

2,434
valkeyself-hosters-by-nightVerified publisher0.1.01 of 1See more

valkey self-hosters-by-night 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
valkey/valkey:9.1.164e361b630ec
perl@5.40.1-6
no fix listed

Open the chart page →

854
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.16d210dc69321e
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

10,987
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

3,346
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

5,515
service-exampleservice-example-10.1.02 of 7See more

service-example service-example-1 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

9,132
serviceexampleserviceexample-chart0.3.03 of 4See more

serviceexample serviceexample-chart 0.3.0

3 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed
tibyandocker/serviceexample:latesta4ad592cea84
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,084
serviceexampleservice-example-helm-chart0.1.02 of 4See more

serviceexample service-example-helm-chart 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

2,332
service-exampleservice-example-jt0.1.11 of 9See more

service-example service-example-jt 0.1.1

1 of the 9 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
janzo83/serviceexample:latestfb3c4ac36f3e
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,584
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,088
my-nginx-appsherif-nginx-app0.1.01 of 1See more

my-nginx-app sherif-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
no fix listed

Open the chart page →

1,879
shopwareshopware-storeVerified publisher2.1.21 of 5See more

shopware shopware-store 2.1.2

1 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
valkey/valkey:83fbd2e3e4b6e
perl@5.40.1-6
no fix listed

Open the chart page →

4,132
pagesshrutiujlan-pages1.0.02 of 3See more

pages shrutiujlan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,261
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.43a82e1f56c8f
perl@5.40.1-6
no fix listed

Open the chart page →

2,700
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

11,751
postgresqlsignoz0.0.21 of 1See more

postgresql signoz 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
perl@5.40.1-6
no fix listed

Open the chart page →

1,686
local-static-provisionersig-storage-local-static-provisioner2.9.01 of 1See more

local-static-provisioner sig-storage-local-static-provisioner 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,280
counter-dhlsikademo0.3.03 of 3See more

counter-dhl sikademo 0.3.0

3 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed
ondrejsika/counter:latestd95eaeee2172
perl@5.40.1-6
no fix listed
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,966
gordy-redissikademo0.1.01 of 1See more

gordy-redis sikademo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

1,004
test-hello-worldsikademo0.1.01 of 1See more

test-hello-world sikademo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
perl@5.40.1-6
no fix listed

Open the chart page →

1,215
hello-worldsikalabs0.17.01 of 1See more

hello-world sikalabs 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
perl@5.40.1-6
no fix listed

Open the chart page →

1,215
hello-world-examplesikalabs0.1.31 of 1See more

hello-world-example sikalabs 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
perl@5.40.1-6
no fix listed

Open the chart page →

1,215
kubernetes-dashboard-gatewaysikalabs0.1.01 of 1See more

kubernetes-dashboard-gateway sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,879
wordpress-mysqlsikalabs0.1.21 of 2See more

wordpress-mysql sikalabs 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
perl@5.40.1-6
no fix listed

Open the chart page →

3,939
simple-websimple-webVerified publisher1.1.11 of 1See more

simple-web simple-web 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,879
bitwardensinextraVerified publisher0.10.21 of 1See more

bitwarden sinextra 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
perl@5.40.1-6
no fix listed

Open the chart page →

1,785
clickhouse-keepersinextraVerified publisher0.7.21 of 1See more

clickhouse-keeper sinextra 0.7.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

2,234
fluentdsinextraVerified publisher1.4.51 of 1See more

fluentd sinextra 1.4.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/fluentd:1.19.33273d13f1e75
perl@5.40.1-6
no fix listed

Open the chart page →

1,134
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
perl@5.40.1-6
no fix listed

Open the chart page →

3,085
mongosqldsinextraVerified publisher0.3.71 of 1See more

mongosqld sinextra 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
perl@5.34.0-3ubuntu1.4
no fix listed

Open the chart page →

2,613
mongosyncsinextraVerified publisher0.4.01 of 1See more

mongosync sinextra 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,874

Container images carrying it

2,391 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/litesql/ha:latest4029479b8ea7
perl@5.40.1-6
no fix listed
1
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
perl@5.40.1-6
no fix listed
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
perl@5.40.1-6
no fix listed
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
perl@5.40.1-6
no fix listed
1
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
perl@5.34.0-3ubuntu1.7
no fix listed
1
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
perl@5.34.0-3ubuntu1.7
no fix listed
1
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
perl@5.34.0-3ubuntu1.7
no fix listed
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.4
1
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
perl@5.40.1-7ubuntu0.1
no fix listed
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
perl@5.40.1-6
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/mcp-hangar/mcp-hangar:2.21.0ee409f91176c
perl@5.40.1-6
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
perl@5.40.1-6
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
perl@5.40.1-6
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
perl@5.40.1-6
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
perl@5.40.1-6
no fix listed
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
perl@5.40.1-6
no fix listed
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
perl@5.40.1-6
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
perl@5.40.1-6
no fix listed
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
perl@5.36.0-7
no fix listed
1
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
perl@5.40.1-6
no fix listed
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
perl@5.34.0-3ubuntu1.3
no fix listed
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
perl@5.40.1-6
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
perl@5.40.1-6
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
perl@5.40.1-6
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
perl@5.40.1-6
no fix listed
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/netbox-community/netbox:v4.7.13f6ab3c93e4e
perl@5.40.1-7ubuntu0.3
no fix listed
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
perl@5.40.1-6
no fix listed
1
ghcr.io/nmshd/backbone-admin-cli:7.2.1f7d095c04a75
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
perl@5.40.1-6
no fix listed
1
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
perl@5.40.1-6
no fix listed
1
ghcr.io/obeone/parcelapp-mcp:0.2.17073131db60b
perl@5.40.1-6
no fix listed
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
perl@5.40.1-6
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.