StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,414
of 17,790 indexed, latest versions
Container images
2,398
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,414 of 17,790 indexed charts deploy, on 2,398 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,377
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,414 by stars
ChartLatestAffected imagesRadar Score
radar-upload-connect-backendradar-baseVerified publisher0.9.11 of 1See more

radar-upload-connect-backend radar-base 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,577
s3-proxyradar-baseVerified publisher0.6.01 of 1See more

s3-proxy radar-base 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,782
pagesranjinigogga1.0.02 of 3See more

pages ranjinigogga 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
rawfile-localpvrawfile0.15.21 of 6See more

rawfile-localpv rawfile 0.15.2

1 of the 6 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
openebs/rawfile-localpv:v0.15.2a39ef27ea28b
perl@5.40.1-6
no fix listed

Open the chart page →

2,897
rdfoxrdfox-helm-chart0.1.22 of 2See more

rdfox rdfox-helm-chart 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
oxfordsemantic/rdfox:5.6db17910eb855
perl@5.30.0-9ubuntu0.2
no fix listed
oxfordsemantic/rdfox-init:5.6baf570ff968d
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

12,884
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

15,570
sqpreadyset-sqp-nightly0.1.0-nightly.202604302 of 3See more

sqp readyset-sqp-nightly 0.1.0-nightly.20260430

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
readysettech/sqp:latest588f3507280e
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
readysettech/sqp-duckdb:latest67a83203ce60
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

3,524
pagesrebecca-pages1.0.02 of 3See more

pages rebecca-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sharanalwar/redchef-backend:latest8d3cab80df49
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,782
ibm-mongodb-enterprise-helmredhat0.3.01 of 1See more

ibm-mongodb-enterprise-helm redhat 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
perl@0:1.28-417.el8_3
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Unicode-Normalize@1.25-396.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb

Open the chart page →

12,382
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

4,245
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
perl@0:1.28-421.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8_6.1
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

16,388
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
perl@0:1.28-420.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

29,564
regoregoOfficialVerified publisher0.1.31 of 1See more

rego rego 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
drorivry4/rego:lateste035d49b15ca
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

2,941
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

6,315
my-nginx-apprepo-for-helm-nginx-app0.1.01 of 1See more

my-nginx-app repo-for-helm-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
perl@5.40.1-6
no fix listed

Open the chart page →

4,273
searxngrestic-pvc-backupVerified publisher0.1.111 of 3See more

searxng restic-pvc-backup 0.1.11

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
valkey/valkey:9.1.1-trixie64e361b630ec
perl@5.40.1-6
no fix listed

Open the chart page →

829
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

7,459
juicepassproxyretsamedocVerified publisher2026.2.41 of 1See more

juicepassproxy retsamedoc 2026.2.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,955
otbrretsamedocVerified publisher26.9.01 of 1See more

otbr retsamedoc 26.9.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
openthread/border-router:v2026.09.07616b9d514de
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

632
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

7,116
spoolmanretsamedocVerified publisher26.9.01 of 1See more

spoolman retsamedoc 26.9.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,797
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:8.2.2f0957bcaa75f
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,624
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

5,869
bookinforgnu1.0.03 of 7See more

bookinfo rgnu 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.14.0ee156b8aefd6
perl@5.22.1-9ubuntu0.6
no fix listed
istio/examples-bookinfo-reviews-v2:1.14.0eab80bcd2132
perl@5.22.1-9ubuntu0.6
no fix listed
istio/examples-bookinfo-reviews-v3:1.14.01e37fca43550
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

20,490
httpbinrgnu1.0.01 of 1See more

httpbin rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
citizenstig/httpbin:latestb81c818ccb86
perl@5.22.1-9
no fix listed

Open the chart page →

11,433
istio-bookinforgnu1.0.23 of 7See more

istio-bookinfo rgnu 1.0.2

3 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.14.0ee156b8aefd6
perl@5.22.1-9ubuntu0.6
no fix listed
istio/examples-bookinfo-reviews-v2:1.14.0eab80bcd2132
perl@5.22.1-9ubuntu0.6
no fix listed
istio/examples-bookinfo-reviews-v3:1.14.01e37fca43550
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

20,490
istio-helloworldrgnu1.0.12 of 2See more

istio-helloworld rgnu 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
istio/examples-helloworld-v1:latest328b237e4fb1
perl@5.36.0-7+deb12u1
no fix listed
istio/examples-helloworld-v2:latest0a7f02b2c7c9
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,452
rke2-ciliumrke2-charts1.20.1031 of 3See more

rke2-cilium rke2-charts 1.20.103

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
perl@5.40.1-7ubuntu0.1
no fix listed

Open the chart page →

1,092
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
perl@5.36.0-7
no fix listed

Open the chart page →

4,925
kresusrm3lVerified publisher0.2.12 of 3See more

kresus rm3l 0.2.1

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
perl@5.36.0-7+deb12u2
no fix listed
bnjbvr/kresus:0.22.137e216b182c8
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

15,681
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

9,327
pagesroccohiggins-pages1.0.02 of 3See more

pages roccohiggins-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,299
reviewboardrock8sVerified publisher0.0.12 of 3See more

reviewboard rock8s 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
perl@5.34.0-3ubuntu1.8
no fix listed
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

6,159
rocketchat-voiprocketchat-server0.1.01 of 1See more

rocketchat-voip rocketchat-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rocketchat/freeswitch:stablecfba5c20a5cc
perl@5.36.0-7+deb12u2
no fix listed

Open the chart page →

5,763
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

9,685
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

13,011
calertromholdings0.0.11 of 1See more

calert romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,690
devtron-enterpriseromholdings48.0.08 of 28See more

devtron-enterprise romholdings 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
perl@5.22.1-9ubuntu0.9
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
perl@5.36.0-7+deb12u3
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
no fix listed

Open the chart page →

68,695
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
perl@5.34.0-3ubuntu1.1
no fix listed

Open the chart page →

4,972
devtron-operatorromholdings0.23.35 of 11See more

devtron-operator romholdings 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
no fix listed

Open the chart page →

33,180
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,959
migration-incluster-cdromholdings0.10.01 of 1See more

migration-incluster-cd romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,908
rommromm-helm-chartVerified publisher1.5.51 of 3See more

romm romm-helm-chart 1.5.5

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mariadb:112439dcd7d140
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4

Open the chart page →

3,420
pagesronan-pages1.0.02 of 3See more

pages ronan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
endeavorrotationalVerified publisher1.3.12 of 2See more

endeavor rotational 1.3.1

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rotationalio/endeavor:1.3.0ac566baddc06
perl@5.36.0-7+deb12u3
no fix listed
rotationalio/quarterdeck:0.16.00e7ad3a031dc
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,240
genoarotationalVerified publisher1.4.01 of 1See more

genoa rotational 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rotationalio/genoa:1.2.03ab583519215
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

990
honurotationalVerified publisher0.5.31 of 1See more

honu rotational 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rotationalio/honu:0.5.069fd30c2e31c
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,180

Container images carrying it

2,398 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/codingducksrl/laravel:8.15be52524664c
perl@5.34.0-3ubuntu1.1
no fix listed
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
perl@5.34.0-3ubuntu1
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
perl@5.36.0-7+deb12u3
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
perl@5.36.0-7+deb12u3
no fix listed
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
perl@5.36.0-7+deb12u3
no fix listed
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
perl@5.30.0-9ubuntu0.2
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
perl@5.30.0-9ubuntu0.2
no fix listed
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
perl@5.30.0-9ubuntu0.2
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
perl@5.36.0-7+deb12u1
no fix listed
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
perl@5.36.0-7+deb12u2
no fix listed
2
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
perl@5.40.1-6
no fix listed
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
perl@5.26.1-6ubuntu0.5
no fix listed
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
perl@5.36.0-7+deb12u3
no fix listed
2
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
perl@5.36.0-7+deb12u1
no fix listed
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
perl@5.36.0-7+deb12u2
no fix listed
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
perl@5.36.0-7+deb12u2
no fix listed
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
perl@5.36.0-7+deb12u1
no fix listed
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
perl@5.36.0-7+deb12u1
no fix listed
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
perl@5.34.0-3ubuntu1
no fix listed
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
perl@5.36.0-7+deb12u2
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
perl@5.36.0-7+deb12u3
no fix listed
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
perl@5.30.0-9ubuntu0.4
no fix listed
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
2
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
perl@5.40.1-6
no fix listed
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
2
quay.io/cilium/cilium:v1.20.22939231d0d3e
perl@5.40.1-7ubuntu0.3
no fix listed
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
perl@5.36.0-7+deb12u3
no fix listed
2
1dev/server:11.9.0cd5b12fe5471
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.4
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
perl@5.36.0-7
no fix listed
1
5200710/hadoop:3.2.3-java8092d3088a5fb
perl@5.30.0-9ubuntu0.5
no fix listed
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
perl@5.26.1-6ubuntu0.3
no fix listed
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
perl@5.40.1-6
no fix listed
1
aboogie/login_test_backend:new9c41a4483ac8
perl@5.36.0-7+deb12u1
no fix listed
1
actualbudget/actual-server:25.3.158fecd9088b7
perl@5.36.0-7+deb12u1
no fix listed
1
adamzammit/limesurvey:7.1.1fdb06d62c22e
perl@5.40.1-6
no fix listed
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
perl@5.30.0-9ubuntu0.2
no fix listed
1
agentarea/agentarea-api:latest9e15e16fa758
perl@5.40.1-6
no fix listed
1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
perl@5.36.0-7+deb12u3
no fix listed
1
agentarea/agentarea-worker:latest1e5cb68ee77a
perl@5.40.1-6
no fix listed
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
perl@5.34.0-3ubuntu1.5
no fix listed
1
aibrix/metadata-service:v0.7.063fb81a64377
perl@5.36.0-7+deb12u1
no fix listed
1
airbyte/manifest-server:7.28.2deec511b51c3
perl@5.36.0-7+deb12u3
no fix listed
1
airbyte/pod-sweeper:1.5.198d2c39d512e
perl@5.36.0-7+deb12u1
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
perl@5.30.0-9ubuntu0.2
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
perl@5.36.0-7
no fix listed
1
akeyless/base:latest759e4289fae8
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
akeyless/base-rhel:0.0.14ba8900a0061
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-Compress-Raw-Bzip2@2.081-1.el8
perl-Compress-Raw-Zlib@2.081-1.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Digest-SHA@1:6.02-1.el8
perl-Encode@4:2.97-3.el8
perl-Encode-Locale@1.05-10.module+el8.3.0+6498+9eecfe51
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-2.el8
perl-IO-Compress@2.081-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:2.096-1.module+el8.10.0+21354+3ad137bb
0:2.096-2.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
1:6.02-2.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:1.05-10.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:2.096-2.module+el8.10.0+24402+ce90c7a0
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.