StackRadar

CVE-2026-9538

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,414
of 17,790 indexed, latest versions
Container images
2,398
deployed by those charts
Fix available
42 of 42
affected packages

Red Hat Security Advisory: perl:5.32 security update

Carried by container images the latest versions of 2,414 of 17,790 indexed charts deploy, on 2,398 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+47 more5.38.2-3.2ubuntu0.4, 5.40.1-6+e62,377
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+4 more0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f75619
perl-Carprpm1.42-396.el80:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Archive-Tarrpm2.38-6.el9, 2.38-6.el9.0.10:2.38-6.el9_8.22
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-2.module+el8.10.0+24402+ce90c7a01
OSV records
DEBIAN-CVE-2026-9538RHSA-2026:48225RLSA-2026:49525UBUNTU-CVE-2026-9538ECHO-e379-3651-bf29
Also known as
USN-8684-1

Charts affected

2,414 by stars
ChartLatestAffected imagesRadar Score
postgresscalified-postgresVerified publisher18.4.01 of 1See more

postgres scalified-postgres 18.4.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
perl@5.40.1-6
no fix listed

Open the chart page →

1,684
factorioschichtelVerified publisher0.1.11 of 1See more

factorio schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
perl@5.40.1-6
no fix listed

Open the chart page →

2,994
mindustryschichtelVerified publisher0.1.11 of 1See more

mindustry schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
pschichtel/mindustry-server:v145.1b543e9c2d371
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

3,268
photonschichtelVerified publisher0.2.01 of 1See more

photon schichtel 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rtuszik/photon-docker:2.4.021549c60f9e6
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

2,870
s3-backupschichtelVerified publisher0.10.01 of 1See more

s3-backup schichtel 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
perl@5.40.1-6
no fix listed

Open the chart page →

2,372
satisfactoryschichtelVerified publisher0.3.31 of 1See more

satisfactory schichtel 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.9464d11e36e10
perl@5.34.0-3ubuntu1.4
no fix listed

Open the chart page →

3,567
vaultwardenschichtelVerified publisher0.9.21 of 1See more

vaultwarden schichtel 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
perl@5.40.1-6
no fix listed

Open the chart page →

1,766
wordpressschichtelVerified publisher0.10.102 of 2See more

wordpress schichtel 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/wordpress:6.9.4-fpmad4a8bae2eb4
perl@5.40.1-6
no fix listed
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
perl@5.40.1-6
no fix listed

Open the chart page →

8,275
otterwikischmitzis0.1.01 of 1See more

otterwiki schmitzis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
redimp/otterwiki:2778bf30da3da
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

3,246
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4

Open the chart page →

6,167
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
typesense/typesense:0.25.1035ccfbc3fd8
perl@5.34.0-3ubuntu1.2
no fix listed

Open the chart page →

4,112
jellyfinschoolguys-helmcharts0.4.21 of 1See more

jellyfin schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.81694ff069f0c
perl@5.40.1-6
no fix listed

Open the chart page →

3,022
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
perl@5.40.1-7build1
no fix listed

Open the chart page →

10,445
satisfactory-serverschoolguys-helmcharts0.1.81 of 1See more

satisfactory-server schoolguys-helmcharts 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

3,469
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,916
unboundschoolguys-helmcharts0.1.11 of 1See more

unbound schoolguys-helmcharts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
mvance/unbound:1.20.04bf67b567f39
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,126
wyoming-faster-whisperschoolguys-helmcharts0.1.41 of 1See more

wyoming-faster-whisper schoolguys-helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rhasspy/wyoming-whisper:3.5.0308b7959a925
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

2,319
wyoming-piperschoolguys-helmcharts0.1.41 of 1See more

wyoming-piper schoolguys-helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
rhasspy/wyoming-piper:2.3.169b7f797ae3a
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,892
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

4,723
search-proxysearch-proxy2026.38.01 of 1See more

search-proxy search-proxy 2026.38.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
perl@5.40.1-6
no fix listed

Open the chart page →

1,286
seawise-dashboardseawiseVerified publisher1.7.11 of 1See more

seawise-dashboard seawise 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
shwcloud/seawise-backup:v1.7.1a97479a54df4
perl@5.40.1-6
no fix listed

Open the chart page →

1,102
pagessekharpkube1.0.02 of 3See more

pages sekharpkube 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

23,041
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
perl@0:1.28-419.el8_4.1
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-Thread-Queue@3.13-1.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
0:3.14-457.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

22,349
postgresself-hosters-by-nightVerified publisher0.14.31 of 1See more

postgres self-hosters-by-night 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
perl@5.40.1-6
no fix listed

Open the chart page →

2,397
valkeyself-hosters-by-nightVerified publisher0.1.01 of 1See more

valkey self-hosters-by-night 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
valkey/valkey:9.1.164e361b630ec
perl@5.40.1-6
no fix listed

Open the chart page →

829
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.16d210dc69321e
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

10,976
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
perl@5.34.0-3ubuntu1.5
no fix listed

Open the chart page →

3,335
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
perl@5.34.0-3ubuntu1.3
no fix listed

Open the chart page →

5,500
service-exampleservice-example-10.1.02 of 7See more

service-example service-example-1 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

9,091
serviceexampleserviceexample-chart0.3.03 of 4See more

serviceexample serviceexample-chart 0.3.0

3 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed
tibyandocker/serviceexample:latesta4ad592cea84
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,018
serviceexampleservice-example-helm-chart0.1.02 of 4See more

serviceexample service-example-helm-chart 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

2,292
service-exampleservice-example-jt0.1.11 of 9See more

service-example service-example-jt 0.1.1

1 of the 9 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
janzo83/serviceexample:latestfb3c4ac36f3e
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

7,201
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
perl@5.36.0-7+deb12u1
no fix listed

Open the chart page →

3,062
my-nginx-appsherif-nginx-app0.1.01 of 1See more

my-nginx-app sherif-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
shopwareshopware-storeVerified publisher2.1.21 of 5See more

shopware shopware-store 2.1.2

1 of the 5 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
valkey/valkey:83fbd2e3e4b6e
perl@5.40.1-6
no fix listed

Open the chart page →

4,091
pagesshrutiujlan-pages1.0.02 of 3See more

pages shrutiujlan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:18.43a82e1f56c8f
perl@5.40.1-6
no fix listed

Open the chart page →

2,662
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
signalen/backend:2.50.14760256000738
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

11,711
postgresqlsignoz0.0.21 of 1See more

postgresql signoz 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
perl@5.40.1-6
no fix listed

Open the chart page →

1,649
local-static-provisionersig-storage-local-static-provisioner2.9.01 of 1See more

local-static-provisioner sig-storage-local-static-provisioner 2.9.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

1,254
counter-dhlsikademo0.3.03 of 3See more

counter-dhl sikademo 0.3.0

3 of the 3 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed
ondrejsika/counter:latestd95eaeee2172
perl@5.40.1-6
no fix listed
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
perl@5.36.0-7+deb12u3
no fix listed

Open the chart page →

4,887
gordy-redissikademo0.1.01 of 1See more

gordy-redis sikademo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
perl@5.40.1-6
no fix listed

Open the chart page →

978
test-hello-worldsikademo0.1.01 of 1See more

test-hello-world sikademo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
perl@5.40.1-6
no fix listed

Open the chart page →

1,189
hello-worldsikalabs0.17.01 of 1See more

hello-world sikalabs 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
perl@5.40.1-6
no fix listed

Open the chart page →

1,189
hello-world-examplesikalabs0.1.31 of 1See more

hello-world-example sikalabs 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
perl@5.40.1-6
no fix listed

Open the chart page →

1,189
kubernetes-dashboard-gatewaysikalabs0.1.01 of 1See more

kubernetes-dashboard-gateway sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
wordpress-mysqlsikalabs0.1.21 of 2See more

wordpress-mysql sikalabs 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
perl@5.40.1-6
no fix listed

Open the chart page →

3,893
simple-websimple-webVerified publisher1.1.11 of 1See more

simple-web simple-web 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
perl@5.40.1-6
no fix listed

Open the chart page →

1,849
bitwardensinextraVerified publisher0.10.21 of 1See more

bitwarden sinextra 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-9538.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
perl@5.40.1-6
no fix listed

Open the chart page →

1,766

Container images carrying it

2,398 by charts deploying them

A fixed version is listed for 42 of the 42 affected packages.

Container imageDigestPackageFixed inUsed by
aktosecurity/akto-agent-guard-anonymizer:1.1.4d4b100cbdc47
perl@5.40.1-6
no fix listed
1
aktosecurity/akto-agent-guard-embedder:1.1.4dbc566b2376c
perl@5.40.1-6
no fix listed
1
aktosecurity/akto-agent-guard-worker:1.1.4666eaffd5362
perl@5.40.1-6
no fix listed
1
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
aktosecurity/akto-threat-detection-backend:latest15ebb75b94dc
perl@5.40.1-7ubuntu0.1
no fix listed
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
perl@5.40.1-7ubuntu0.1
no fix listed
1
aktosecurity/data-ingestion-service213aded7adc5
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
perl@5.40.1-7ubuntu0.1
no fix listed
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
perl@5.40.1-7ubuntu0.1
no fix listed
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
perl@5.40.1-7ubuntu0.1
no fix listed
1
alazidis/stornx:1.1.1602d4f7f090c
perl@5.36.0-7+deb12u3
no fix listed
1
allegroai/clearml:2.0.0-613713ae38f7daf
perl@5.36.0-7+deb12u1
no fix listed
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
perl@5.26.1-6ubuntu0.5
no fix listed
1
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
perl@5.34.0-3ubuntu1.4
no fix listed
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
perl@5.34.0-3ubuntu1.2
no fix listed
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
perl@5.34.0-3ubuntu1.4
no fix listed
1
andrianrf/backoffice:latest047a7837651e
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-3.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb
1
anguda/ant-media:2.5c435285fc241
perl@5.30.0-9ubuntu0.3
no fix listed
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
perl@5.36.0-7
no fix listed
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
perl@5.40.1-6
no fix listed
1
antrea/flow-aggregator:v2.7.0065193e7572f
perl@5.38.2-3.2ubuntu0.3
5.38.2-3.2ubuntu0.4
1
anujdatar/cups:25.07.01685df04a643b
perl@5.36.0-7+deb12u2
no fix listed
1
apache/activemq-artemis:2.44.00305c26f19ed
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
apache/activemq-artemis:2.37.0bae523439ee3
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
apache/airflow:2.8.4-python3.964e58748b6b9
perl@5.36.0-7+deb12u1
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
perl@5.36.0-7+deb12u1
no fix listed
1
apache/airflow:2.8.1e5560ad0b86e
perl@5.36.0-7+deb12u1
no fix listed
1
apache/apisix:3.16.0-ubuntu5e47692cac00
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
apache/camel-k:2.11.0d173e7efe258
perl@5.40.1-7ubuntu0.1
no fix listed
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
perl@5.34.0-3ubuntu1.5
no fix listed
1
apache/hertzbeat:1.8.075d48a62748f
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
perl@5.38.2-3.2ubuntu0.2
5.38.2-3.2ubuntu0.4
1
apache/iotdb:0.13.3-nodeafa47bf1692a
perl@5.30.0-9ubuntu0.2
no fix listed
1
apache/nifi-registry:1.27.063b8e3e40742
perl@5.34.0-3ubuntu1.3
no fix listed
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
perl@5.34.0-3ubuntu1.2
no fix listed
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
perl@5.30.0-9ubuntu0.2
no fix listed
1
apachepulsar/pulsar:3.0.79c9947de139d
perl@5.34.0-3ubuntu1.3
no fix listed
1
apachepulsar/pulsar:2.9.0d056c89b7131
perl@5.30.0-9ubuntu0.2
no fix listed
1
apachepulsar/pulsar:2.8.2d538416d5afe
perl@5.30.0-9ubuntu0.2
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
perl@5.34.0-3ubuntu1.4
no fix listed
1
apache/rocketmq:5.3.0434d8398f996
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.4
1
apache/rocketmq-exporter:0.0.2c8fb51195444
perl@5.34.0-3ubuntu1.3
no fix listed
1
apache/skywalking-oap-server:9.2.0133d35d2c263
perl@5.34.0-3ubuntu1
no fix listed
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
perl@5.30.0-9ubuntu0.2
no fix listed
1
apache/skywalking-ui:9.2.0295f1dc87d98
perl@5.34.0-3ubuntu1
no fix listed
1
apache/skywalking-ui:8.9.180530f0308a5
perl@5.30.0-9ubuntu0.2
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.