StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,417
of 17,787 indexed, latest versions
Container images
2,395
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,417 of 17,787 indexed charts deploy, on 2,395 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,374
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,417 by stars
ChartLatestAffected imagesRadar Score
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,749
kuma-ingress-watcherkuma-ingress-watcherVerified publisher1.4.01 of 1See more

kuma-ingress-watcher kuma-ingress-watcher 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,668
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

12,477
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

114,025
ohifkylesferrazzaVerified publisher0.1.01 of 2See more

ohif kylesferrazza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jodogne/orthanc-plugins:latest6ff510aa29c2
perl@5.40.1-6
no fix listed

Open the chart page →

3,524
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,551
api-gatewaylabs64io-helm-chartsVerified publisher0.12.01 of 1See more

api-gateway labs64io-helm-charts 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
labs64/traefik-authproxy:0.0.3dfc6086dfbce
perl@5.40.1-6
no fix listed

Open the chart page →

1,018
auditflowlabs64io-helm-chartsVerified publisher0.12.11 of 3See more

auditflow labs64io-helm-charts 0.12.1

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
labs64/auditflowdigest-pinnedc7b26d3ca11c
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,487
checkoutlabs64io-helm-chartsVerified publisher0.8.01 of 3See more

checkout labs64io-helm-charts 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

1,638
payment-gatewaylabs64io-helm-chartsVerified publisher0.8.02 of 2See more

payment-gateway labs64io-helm-charts 0.8.0

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
labs64/payment-gateway:0.0.10c66feefca17
perl@5.40.1-7ubuntu0.1
no fix listed
library/postgres:184ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

2,708
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,011
lgtm-stacklgtm-stackVerified publisher0.1.31 of 8See more

lgtm-stack lgtm-stack 0.1.3

1 of the 8 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.10f4434c92b3e
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

5,614
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

35,058
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,456
halitesql0.1.51 of 2See more

ha litesql 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/litesql/ha:latest4029479b8ea7
perl@5.40.1-6
no fix listed

Open the chart page →

1,111
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4

Open the chart page →

7,915
clickhouseliwenhe1.0.11 of 3See more

clickhouse liwenhe 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.14ccf9c2b5e3f2
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

6,766
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,216
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,763
plexluiscajl1.0.11 of 2See more

plex luiscajl 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:latest7f9a1d574958
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

848
voice-biometricslumenvox2.0.112 of 26See more

voice-biometrics lumenvox 2.0.1

12 of the 26 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-assure-identity:2.0.0147854a3c916
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-audit:2.0.079428add7f38
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-binary-storage:2.0.053decadc102d
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-deployment:2.0.0ea8110886d38
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-management-api:2.0.0b9a23345eabd
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-reporting:2.0.07a9ffdc2178a
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-voice-verifier:2.0.014170ad34903
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

71,216
actualbudgetm0nsterrr-actualbudgetVerified publisher2.10.01 of 1See more

actualbudget m0nsterrr-actualbudget 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,102
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

5,747
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,741
redismagefleet-redis0.1.01 of 1See more

redis magefleet-redis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:7.274566c6910d1
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,061
magentomagento3.2.33 of 12See more

magento magento 3.2.3

3 of the 12 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
perl@5.30.0-9ubuntu0.5
no fix listed
library/rabbitmq:4.1.0-management935b3f84c1e4
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
library/redis:7.274566c6910d1
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

13,582
maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,014
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

19,192
mcpmcp-chartsVerified publisher0.0.233 of 7See more

mcp mcp-charts 0.0.23

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
perl@5.40.1-6
no fix listed
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
perl@5.40.1-6
no fix listed
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

6,994
jellyfinmedia-servarrVerified publisher0.16.01 of 2See more

jellyfin media-servarr 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
perl@5.40.1-6
no fix listed

Open the chart page →

2,764
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

4,184
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
perl@5.40.1-6build1
no fix listed

Open the chart page →

11,108
model-manager-loadermodel-manager-loader1.27.01 of 1See more

model-manager-loader model-manager-loader 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
perl@5.40.1-6
no fix listed

Open the chart page →

2,678
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

13,763
redminemt1905027.3.42 of 3See more

redmine mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
perl@5.40.1-6
no fix listed
library/redmine:6.1.204ac44a2595b
perl@5.40.1-6
no fix listed

Open the chart page →

7,552
12factormyaVerified publisher24.1.21 of 1See more

12factor mya 24.1.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
my-react-appmy-react-app0.1.51 of 1See more

my-react-app my-react-app 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
n3uronn3uronVerified publisher0.3.51 of 1See more

n3uron n3uron 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
n3uronhub/n3uron:v1.22.4423a0bdd9cb9
perl@5.40.1-6
no fix listed

Open the chart page →

1,896
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

3,729
spring-helmnaveenalla-springboot1.0.01 of 2See more

spring-helm naveenalla-springboot 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
perl@5.40.1-6
no fix listed

Open the chart page →

1,638
clowder2ncsaVerified publisher1.9.75 of 12See more

clowder2 ncsa 1.9.7

5 of the 12 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
perl@5.36.0-7+deb12u1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
perl@5.36.0-7+deb12u1
no fix listed
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
perl@5.36.0-7+deb12u3
no fix listed
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
perl@5.36.0-7+deb12u3
no fix listed
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

37,441
nginx-chartnginx-chart-testVerified publisher0.1.11 of 1See more

nginx-chart nginx-chart-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
helm-composenousefreakVerified publisher0.1.32 of 2See more

helm-compose nousefreak 0.1.3

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:10.8.2-focal490f01279be1
perl@5.30.0-9ubuntu0.2
no fix listed
library/wordpress:latest5a93c470ae82
perl@5.40.1-6
no fix listed

Open the chart page →

14,324
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,051
onechartonechart-slVerified publisher0.76.01 of 1See more

onechart onechart-sl 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,839
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
perl@5.36.0-7
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

14,862
dhcp-serveropencord1.0.21 of 1See more

dhcp-server opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
networkboot/dhcpd:lateste99bbfbd6fb2
perl@5.34.0-3ubuntu1
no fix listed

Open the chart page →

4,205
librechatopenshift1.9.02 of 3See more

librechat openshift 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,833
opentelemetry-demoopentelemetry-helmVerified publisher0.41.17 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

7 of the 34 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
perl@5.40.1-6
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-frontend-proxy1c53bfb59697
perl@5.34.0-3ubuntu1.7
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-mcp654f860148ba
perl@5.40.1-6
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
perl@5.40.1-6
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-accounting74c490f862da
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
ghcr.io/open-telemetry/demo:3.0.0-agentdf5ee05e23e3
perl@5.40.1-6
no fix listed
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

22,678
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

6,899

Container images carrying it

2,395 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
library/mongo:7.0-jammy:7-jammy406a4fdca9fc
perl@5.34.0-3ubuntu1.7
no fix listed
2
library/mongo:5.041108d183e97
perl@5.30.0-9ubuntu0.5
no fix listed
2
library/mongo:4.2.358b25d51baa1
perl@5.26.1-6ubuntu0.3
no fix listed
2
library/mongo:7b096b4cb9269
perl@5.34.0-3ubuntu1.8
no fix listed
2
library/mongo:7.0b6421fd6d1c5
perl@5.34.0-3ubuntu1.7
no fix listed
2
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
perl@5.40.1-6
no fix listed
2
library/nginx:latest6e23479198b9
perl@5.40.1-6
no fix listed
2
library/nginx:1.27.098f8ec75657d
perl@5.36.0-7+deb12u1
no fix listed
2
library/nginx:1.29.49dd288848f44
perl@5.40.1-6
no fix listed
2
library/phpmyadmin:5.2.16e75aa8f767c
perl@5.36.0-7+deb12u1
no fix listed
2
library/postgres:17-bookworm051f7b7b3abd
perl@5.36.0-7+deb12u3
no fix listed
2
library/postgres:16.109f23e02d766
perl@5.36.0-7+deb12u1
no fix listed
2
library/postgres:18.11090bc3a8ccf
perl@5.40.1-6
no fix listed
2
library/postgres:16.24aea012537ed
perl@5.36.0-7+deb12u1
no fix listed
2
library/postgres:18.06f3e42ad37de
perl@5.40.1-6
no fix listed
2
library/postgres:16.4e62fbf9d3e2b
perl@5.36.0-7+deb12u1
no fix listed
2
library/python:3.14-slim:3-slimcad9a2c87176
perl@5.40.1-6
no fix listed
2
library/python:3.7eedf63967cdb
perl@5.36.0-7
no fix listed
2
library/rabbitmq:4.1.0-management935b3f84c1e4
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
2
library/rabbitmq:3.12.1-managementf020c06da226
perl@5.34.0-3ubuntu1.2
no fix listed
2
library/redis:7.2.3a7cee7c8178f
perl@5.36.0-7+deb12u1
no fix listed
2
library/redis:8.2.2f0957bcaa75f
perl@5.36.0-7+deb12u3
no fix listed
2
library/redmine:6.1.3-trixief474a901faec
perl@5.40.1-6
no fix listed
2
library/ubuntu:16.04:xenial1f1a2d56de1d
perl@5.22.1-9ubuntu0.9
no fix listed
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
perl@5.40.1-6
no fix listed
2
library/zookeeper:3.9.5f258365d4882
perl@5.34.0-3ubuntu1.7
no fix listed
2
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
perl@5.22.1-9ubuntu0.6
no fix listed
2
localstack/localstack-pro:latest4aef81c53168
perl@5.40.1-6
no fix listed
2
locustio/locust:2.32.2a0d4b88e42c1
perl@5.36.0-7+deb12u1
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
perl@5.36.0-7+deb12u3
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
perl@5.36.0-7+deb12u3
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
perl@5.36.0-7+deb12u3
no fix listed
2
mbentley/omada-controller:4.3f4e682274bed
perl@5.26.1-6ubuntu0.7
no fix listed
2
meshery/meshery:stable-latest44b64ee128fb
perl@5.36.0-7+deb12u3
no fix listed
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
perl@5.30.0-9build1
no fix listed
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
perl@5.36.0-7+deb12u1
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
perl@5.36.0-7
no fix listed
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
perl@5.36.0-7
no fix listed
2
nacos/nacos-server:latest1c191c30c8cd
perl@5.40.1-7ubuntu0.1
no fix listed
2
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
perl@5.26.1-6
no fix listed
2
nginxinc/nginx-unprivileged:stablecb92301e719d
perl@5.40.1-6
no fix listed
2
obolnetwork/charon:v1.10.0278c7e2897b6
perl@5.40.1-6
no fix listed
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
perl@5.30.0-9ubuntu0.2
no fix listed
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
perl@5.22.1-9ubuntu0.6
no fix listed
2
opea/embedding-tei:1.05c9639de61c1
perl@5.36.0-7+deb12u1
no fix listed
2
opea/reranking-tei:1.0e48613afb191
perl@5.36.0-7+deb12u1
no fix listed
2
opea/retriever-redis:1.0eb746b263705
perl@5.36.0-7+deb12u1
no fix listed
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
perl@5.36.0-7+deb12u1
no fix listed
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
perl@5.36.0-7+deb12u1
no fix listed
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
perl@5.36.0-7+deb12u1
no fix listed
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.