StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,403
of 17,797 indexed, latest versions
Container images
2,378
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,403 of 17,797 indexed charts deploy, on 2,378 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,357
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,403 by stars
ChartLatestAffected imagesRadar Score
laraveldevops0.10.32 of 4See more

laravel devops 0.10.3

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:10.9.4fbb8456ebdb1
perl@5.34.0-3ubuntu1.1
no fix listed
ghcr.io/codingducksrl/laravel:8.15be52524664c
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

29,235
wordpressdevops0.12.01 of 4See more

wordpress devops 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
perl@5.34.0-3ubuntu1
no fix listed

Open the chart page →

13,047
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,703
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

13,033
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,699
devtron-enterprisedevtron48.0.08 of 28See more

devtron-enterprise devtron 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
perl@5.22.1-9ubuntu0.9
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
perl@5.36.0-7+deb12u3
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
no fix listed

Open the chart page →

68,765
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

4,979
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,981
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,927
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,703
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

13,033
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,699
devtron-enterprisedevtron-labs48.0.08 of 28See more

devtron-enterprise devtron-labs 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
perl@5.22.1-9ubuntu0.9
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
perl@5.36.0-7+deb12u3
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
no fix listed

Open the chart page →

68,765
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

4,979
devtron-operatordevtron-labs0.23.35 of 11See more

devtron-operator devtron-labs 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
no fix listed

Open the chart page →

33,219
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,981
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,927
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.03 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
perl@5.26.1-6ubuntu0.5
no fix listed
library/rabbitmq:3-managemente582c0bc7766
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

27,676
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

4,083
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
perl@5.36.0-7+deb12u1
no fix listed
langgenius/dify-sandbox:0.2.009b7e8705673
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

19,513
pagesdipak1.0.02 of 3See more

pages dipak 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,262
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
perl@5.40.1-6
no fix listed

Open the chart page →

7,549
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

2,402
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
perl@5.36.0-7
no fix listed

Open the chart page →

7,322
ownclouddjjudas21Verified publisher0.3.233 of 3See more

owncloud djjudas21 0.3.23

3 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
perl@5.36.0-7+deb12u1
no fix listed
owncloud/server:10.16.3b3f9efdcd7f7
perl@5.34.0-3ubuntu1.7
no fix listed
valkey/valkey:8.1.481db6d39e1bb
perl@5.40.1-6
no fix listed

Open the chart page →

10,199
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

17,129
spoolmandjjudas21Verified publisher0.1.81 of 1See more

spoolman djjudas21 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.24.042135965c42d
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,858
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
perl@5.40.1-6
no fix listed

Open the chart page →

5,304
webtreesdjjudas21Verified publisher3.0.01 of 1See more

webtrees djjudas21 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
perl@5.40.1-6
no fix listed

Open the chart page →

6,012
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
perl@5.36.0-7
no fix listed

Open the chart page →

14,713
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,845
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,845
dnation-kubernetes-monitoring-stackdnationcloud4.0.21 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

1 of the 17 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

21,767
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

9,003
dnsmasq-k8sdnsmasq-k8s1.4.11 of 1See more

dnsmasq-k8s dnsmasq-k8s 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
perl@5.40.1-6
no fix listed

Open the chart page →

3,075
dominodomino-iisasVerified publisher0.3.13 of 3See more

domino domino-iisas 0.3.1

3 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
perl@5.40.1-6
no fix listed
ghcr.io/iisas/domino-frontend:k8s8e53861be292
perl@5.36.0-7+deb12u3
no fix listed
ghcr.io/iisas/domino-rest:latest3009350bfc11
perl@5.40.1-6
no fix listed

Open the chart page →

10,393
exim4dossif0.2.01 of 1See more

exim4 dossif 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
tianon/exim4:latestb489049cdbca
perl@5.40.1-6
no fix listed

Open the chart page →

1,477
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

24,986
healthchecksdoubanVerified publisher1.0.101 of 2See more

healthchecks douban 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
healthchecks/healthchecks:latestaa08a61b0dcf
perl@5.40.1-6
no fix listed

Open the chart page →

1,731
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,848
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.03 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
perl@5.26.1-6ubuntu0.5
no fix listed
library/rabbitmq:3-managemente582c0bc7766
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

24,781
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
perl@5.34.0-3ubuntu1
no fix listed

Open the chart page →

30,778
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,465
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
perl@5.40.1-6
no fix listed

Open the chart page →

3,490
rundeckdwardu-helm-charts0.3.42 of 2See more

rundeck dwardu-helm-charts 0.3.4

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
no fix listed
rundeck/rundeck:3.2.74d64fe56f767
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

19,859
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,364
base-consensusdysnixVerified publisher0.2.01 of 1See more

base-consensus dysnix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

1,768
bitcoinddysnixVerified publisher0.4.31 of 2See more

bitcoind dysnix 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

1,987
gcp-local-nvme-raiddysnixVerified publisher0.2.01 of 2See more

gcp-local-nvme-raid dysnix 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/ubuntu:24.0433ceb71981b6
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

688
gcp-local-ssd-raiddysnixVerified publisher0.1.71 of 2See more

gcp-local-ssd-raid dysnix 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

2,417

Container images carrying it

2,378 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/steadybit/agent:2.4.52bc7b260e44e
perl@5.40.1-6
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
perl@5.40.1-6
no fix listed
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
perl@5.36.0-7+deb12u1
no fix listed
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
perl@5.40.1-6
no fix listed
1
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/topolvm/pie:0.18.0aa467443e407
perl@5.34.0-3ubuntu1.7
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
perl@5.34.0-3ubuntu1.7
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
perl@5.34.0-3ubuntu1.3
no fix listed
1
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
perl@5.40.1-6
no fix listed
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
perl@5.40.1-6
no fix listed
1
ghcr.io/utkuozdemir/nvidia_gpu_exporter:1.5.0d75967a4dd72
perl@5.40.1-7build1
no fix listed
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
perl@5.40.1-6
no fix listed
1
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
perl@5.36.0-7+deb12u2
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
perl@5.34.0-3ubuntu1.3
no fix listed
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
perl@5.34.0-3ubuntu1.3
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
perl@5.34.0-3ubuntu1.3
no fix listed
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
perl@5.36.0-7
no fix listed
1
ghcr.io/wearefrank/frank-gateway:1.0.05ccf797ccdf1
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
ghcr.io/wekan/ferretdb:latest6cb94aa01999
perl@5.40.1-6
no fix listed
1
ghcr.io/wekan/wekan:v11.83137951e3fb40
perl@5.40.1-6+deb13u1
no fix listed
1
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
perl@5.40.1-6
no fix listed
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
perl@5.36.0-7+deb12u2
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
perl@5.36.0-7+deb12u3
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
perl@5.36.0-7
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
perl@5.36.0-7+deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.