StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,414
of 17,790 indexed, latest versions
Container images
2,398
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,414 of 17,790 indexed charts deploy, on 2,398 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,377
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,414 by stars
ChartLatestAffected imagesRadar Score
gitops-promotergitops-promoterOfficialVerified publisher0.17.01 of 2See more

gitops-promoter gitops-promoter 0.17.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
perl@5.40.1-6
no fix listed

Open the chart page →

2,917
glpiglpi-conteiner0.1.03 of 3See more

glpi glpi-conteiner 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:latestdd9b303aed4f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/phpmyadmin:latest3a8a8d6b5289
perl@5.40.1-6
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

12,359
grafana-mcpgrafana-communityVerified publisher0.23.21 of 1See more

grafana-mcp grafana-community 0.23.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
grafana/mcp-grafana:1.4.2f87fa67a561f
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,090
dolibarrhelmforgeVerified publisher1.2.181 of 3See more

dolibarr helmforge 1.2.18

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dolibarr/dolibarr:24.0.069ec52e3b7ef
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,172
karakeephelmforgeVerified publisher1.2.92 of 3See more

karakeep helmforge 1.2.9

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,557
openhabhelmforgeVerified publisher1.2.01 of 1See more

openhab helmforge 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
openhab/openhab:5.2.1bfd4a60e90da
perl@5.40.1-6
no fix listed

Open the chart page →

3,664
postgresqlhelmforgeVerified publisher2.0.51 of 1See more

postgresql helmforge 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

1,649
umamihelmforgeVerified publisher2.3.31 of 3See more

umami helmforge 2.3.3

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

2,050
openctihelm-openctiVerified publisher3.0.91 of 8See more

opencti helm-opencti 3.0.9

1 of the 8 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

3,407
hertzbeathertzbeatOfficialVerified publisher1.8.13 of 4See more

hertzbeat hertzbeat 1.8.1

3 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
apache/hertzbeat-collector:1.8.0a2bab1be574c
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
library/postgres:159b1d34adbce1
perl@5.40.1-6
no fix listed

Open the chart page →

14,181
infrahubinfrahubVerified publisher4.33.24 of 5See more

infrahub infrahub 4.33.2

4 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
perl@5.36.0-7+deb12u2
no fix listed
library/neo4j:2026.05.06c162e2432f8
perl@5.40.1-6
no fix listed

Open the chart page →

10,522
plexk8s-home-lab-repo7.3.11 of 1See more

plex k8s-home-lab-repo 7.3.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

1,729
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

6,350
kubeflowkubeflow1.6.25 of 45See more

kubeflow kubeflow 1.6.2

5 of the 45 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
perl@5.26.1-6ubuntu0.5
no fix listed
istio/proxyv2:1.14.1df69c1a7af7c
perl@5.30.0-9ubuntu0.2
no fix listed
library/python:3.7eedf63967cdb
perl@5.36.0-7
no fix listed
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
perl@5.22.1-9ubuntu0.6
no fix listed
gcr.io/tfx-oss-public/ml_metadata_store_server:1.5.0db8691752b4c
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

97,217
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

10,573
testkubekubeshop2.13.22 of 5See more

testkube kubeshop 2.13.2

2 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
kubeshop/testkube-minio:2025.10d8e1af6aca99
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,151
librechatlibrechat-openshiftVerified publisher1.9.02 of 3See more

librechat librechat-openshift 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,849
libredb-studiolibredb-studioVerified publisher0.1.631 of 1See more

libredb-studio libredb-studio 0.1.63

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
perl@5.40.1-6
no fix listed

Open the chart page →

1,244
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

4,070
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

7,997
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
gradiant/open5gs-dbctl:0.10.3332031245fce
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.4

Open the chart page →

9,305
ubuntuopen-charts1.2.11 of 1See more

ubuntu open-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/ubuntu:22.042edbbc5dc405
perl@5.34.0-3ubuntu1.7
no fix listed

Open the chart page →

1,579
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

8,777
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

10,563
sops-secrets-operatorsops-secrets-operatorVerified publisher0.28.11 of 1See more

sops-secrets-operator sops-secrets-operator 0.28.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

832
steampipe-powerpipe-kubernetessteampipe-powerpipe-kubernetesVerified publisher0.13.12 of 2See more

steampipe-powerpipe-kubernetes steampipe-powerpipe-kubernetes 0.13.1

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,530
topolvmtopolvmVerified publisher17.2.01 of 1See more

topolvm topolvm 17.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
perl@5.34.0-3ubuntu1.7
no fix listed

Open the chart page →

2,374
uffizzi-appuffizzi-app1.3.01 of 14See more

uffizzi-app uffizzi-app 1.3.0

1 of the 14 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

19,434
reposilitevolker-raschekVerified publisher1.0.01 of 1See more

reposilite volker-raschek 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.5.264128c2d7a6ba
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

3,002
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
gcr.io/google_containers/kubernetes-dashboard-init-amd64:v1.0.0fbe12aa24de6
perl@5.22.1-9
no fix listed

Open the chart page →

13,578
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
perl@5.36.0-7
no fix listed

Open the chart page →

9,775
matrixzekker6Verified publisher3.30.01 of 4See more

matrix zekker6 3.30.0

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.160.078de1d10bef0
perl@5.40.1-6
no fix listed

Open the chart page →

5,579
zenmlzenml0.96.41 of 1See more

zenml zenml 0.96.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
zenmldocker/zenml-server:0.96.409027a6312ee
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,294
eshoponabpabp-charts1.0.01 of 15See more

eshoponabp abp-charts 1.0.0

1 of the 15 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:4.2699d652ed674
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

19,812
changedetectionalekcVerified publisher0.14.41 of 1See more

changedetection alekc 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,612
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

8,254
vaultwardenandrenarchyVerified publisher6.28.01 of 1See more

vaultwarden andrenarchy 6.28.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.31587c45feaa4
perl@5.40.1-6
no fix listed

Open the chart page →

1,503
tt-rssangelnu7.0.01 of 2See more

tt-rss angelnu 7.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,234
limesurveyarea-42Verified publisher0.3.952 of 2See more

limesurvey area-42 0.3.95

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
adamzammit/limesurvey:7.1.1fdb06d62c22e
perl@5.40.1-6
no fix listed
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

4,775
auto-deploy-appav1o-chartsVerified publisher0.15.41 of 1See more

auto-deploy-app av1o-charts 0.15.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
perl@5.22.1-9
no fix listed

Open the chart page →

11,015
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

8,026
geoservercloudcamptocamp23.0.17 of 7See more

geoservercloud camptocamp2 3.0.1

7 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:3.0.1.1de0b20bd2a43
perl@5.40.1-7ubuntu0.1
no fix listed
geoservercloud/geoserver-cloud-gwc:3.0.1.1b04ed89b5d2b
perl@5.40.1-7ubuntu0.1
no fix listed
geoservercloud/geoserver-cloud-rest:3.0.1.1318254b52f96
perl@5.40.1-7ubuntu0.1
no fix listed
geoservercloud/geoserver-cloud-wcs:3.0.1.14f077124f591
perl@5.40.1-7ubuntu0.1
no fix listed
geoservercloud/geoserver-cloud-webui:3.0.1.14f91e3048ac8
perl@5.40.1-7ubuntu0.1
no fix listed
geoservercloud/geoserver-cloud-wfs:3.0.1.1299f0d6232d1
perl@5.40.1-7ubuntu0.1
no fix listed
geoservercloud/geoserver-cloud-wms:3.0.1.15164f687ce4d
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

10,861
thingsboardcetic0.1.21 of 2See more

thingsboard cetic 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
thingsboard/tb-postgres:latest2d17e4e36edc
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,256
lighthousechronicleVerified publisher0.0.81 of 1See more

lighthouse chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sigp/lighthouse:v7.1.0870934e38931
perl@5.34.0-3ubuntu1.4
no fix listed

Open the chart page →

1,963
ghostcloudpirates-ghostVerified publisher0.20.222 of 3See more

ghost cloudpirates-ghost 0.20.22

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
perl@5.36.0-7+deb12u3
no fix listed
library/mariadb:12.0.25b6a1eac15b8
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

7,267
clowardenclowarden0.2.31 of 4See more

clowarden clowarden 0.2.3

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
perl@5.40.1-6
no fix listed

Open the chart page →

5,632
convertigoconvertigoOfficialVerified publisher8.4.33 of 5See more

convertigo convertigo 8.4.3

3 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
perl@5.36.0-7+deb12u1
no fix listed
library/convertigo:8.4.3ae605bfcda05
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/couchdb:3.4.22817ad50b5c5
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

17,569
cosmocosmo-platformOfficialVerified publisher0.20.05 of 10See more

cosmo cosmo-platform 0.20.0

5 of the 10 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.6.2-debian-12-r3dcc172c6c55f
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
perl@5.36.0-7+deb12u2
no fix listed
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
perl@5.36.0-7+deb12u1
no fix listed
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
perl@5.36.0-7+deb12u1
no fix listed
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

29,070
crossviewcrossviewOfficialVerified publisher4.6.01 of 2See more

crossview crossview 4.6.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

1,814
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
perl@5.40.1-6
no fix listed

Open the chart page →

9,395

Container images carrying it

2,398 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
perl@5.26.1-6ubuntu0.5
no fix listed
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
ghcr.io/linuxserver/ombi:4.53.50caadf03b804
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
perl@5.34.0-3ubuntu1
no fix listed
1
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.4
1
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
perl@5.26.1-6ubuntu0.5
no fix listed
1
ghcr.io/litesql/ha:latest4029479b8ea7
perl@5.40.1-6
no fix listed
1
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
perl@5.40.1-6
no fix listed
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
perl@5.40.1-6
no fix listed
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
perl@5.40.1-6
no fix listed
1
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
perl@5.34.0-3ubuntu1.7
no fix listed
1
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
perl@5.34.0-3ubuntu1.7
no fix listed
1
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
perl@5.34.0-3ubuntu1.7
no fix listed
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.4
1
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
perl@5.40.1-7ubuntu0.1
no fix listed
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
perl@5.40.1-6
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/mcp-hangar/mcp-hangar:2.19.14f92e139cd33
perl@5.40.1-6
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
perl@5.40.1-6
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
perl@5.40.1-6
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
perl@5.40.1-6
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
perl@5.40.1-6
no fix listed
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
perl@5.40.1-6
no fix listed
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
perl@5.40.1-6
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/middleware-labs/mw-kube-agent:1.21.0ff23f452813a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
perl@5.40.1-6
no fix listed
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
perl@5.36.0-7
no fix listed
1
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/monicahq/monica-next:main8be69156acbb
perl@5.40.1-6
no fix listed
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
perl@5.34.0-3ubuntu1.3
no fix listed
1
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
perl@5.40.1-6
no fix listed
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/music-assistant/server:2.10.3885872224fa5
perl@5.40.1-6
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
perl@5.40.1-6
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
perl@5.40.1-6
no fix listed
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/netbox-community/netbox:v4.7.01685e91c61bb
perl@5.40.1-7ubuntu0.3
no fix listed
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
perl@5.40.1-6
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.