StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

6,220
mollysocketmollysocketVerified publisher0.2.81 of 1See more

mollysocket mollysocket 0.2.8

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

3,028
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

5,217
camera-viewermoreillonVerified publisher0.2.12 of 4See more

camera-viewer moreillon 0.2.1

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
moreillon/camera-viewer:lateste418cc694bd5
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

11,694
group-managermoreillonVerified publisher0.4.42 of 3See more

group-manager moreillon 0.4.4

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
moreillon/group-manager-front:v3.3.1c9f85db3baa5
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

9,886
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5

Open the chart page →

10,998
user-manager-mongodbmoreillonVerified publisher0.6.23 of 4See more

user-manager-mongodb moreillon 0.6.2

3 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
moreillon/user-manager-front:v5.0.3b067dbbbb6af
perl@5.36.0-7
5.36.0-7+deb12u3
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

23,263
user-manager-neo4jmoreillonVerified publisher0.9.74 of 6See more

user-manager-neo4j moreillon 0.9.7

4 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
moreillon/group-manager-front:v3.3.1c9f85db3baa5
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
moreillon/user-manager:v5.0.2e1c9bfab5c16
perl@5.36.0-7
5.36.0-7+deb12u3
moreillon/user-manager-front:v5.1.06597e6b98d21
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

30,195
genericmorremeyer8.0.01 of 1See more

generic morremeyer 8.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/nginx:1.25.167f9a4f10d14
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

5,602
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

25,989
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

15,731
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

6,646
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

13,711
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

8,946
pagesmuthu-pages1.0.02 of 3See more

pages muthu-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

12,861
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

12,861
clickhousemyaVerified publisher0.2403.11 of 1See more

clickhouse mya 0.2403.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.2ed9640bfff07
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,597
cognativemyaVerified publisher0.2403.31 of 3See more

cognative mya 0.2403.3

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.2ed9640bfff07
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

7,348
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
perl@0:1.28-420.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
0:1.28-423.el8_10
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb

Open the chart page →

9,149
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

9,341
my-helm-chartmy-helm-charts-2024Verified publisher0.1.01 of 1See more

my-helm-chart my-helm-charts-2024 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
shamimkuet/nginx:1.0.2b82902a76a04
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,383
Practica_4_helmmy-heml-appVerified publisher0.1.03 of 7See more

Practica_4_helm my-heml-app 0.1.0

3 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
perl@5.26.1-6ubuntu0.6
no fix listed
library/mongo:5.0.6-focal8e70544b6c76
perl@5.30.0-9ubuntu0.2
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

27,812
mystoremystore-chart0.1.02 of 3See more

mystore mystore-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hazegoodlife/haaze:veggiesite50f02d2d5d4d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
hazegoodlife/haaze:milksite8d4c63169e14
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

8,776
myweatherhelmmyweather1.3.112 of 7See more

myweatherhelm myweather 1.3.11

2 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hecrom/myweatherangularclient:1.3.11bb0372939c19
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

17,411
smallandnaj980.0.51 of 1See more

smalland naj98 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

3,024
pagesnarain1.0.02 of 3See more

pages narain 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
pagesnarasimha-pages1.0.02 of 3See more

pages narasimha-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

12,839
pagesnavin-brixton1.0.02 of 3See more

pages navin-brixton 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
incorencsaVerified publisher1.38.02 of 29See more

incore ncsa 1.38.0

2 of the 29 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
bitnamilegacy/postgresql:16.4.03ba6e6f11388
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

15,408
smilencsaVerified publisher1.1.07 of 23See more

smile ncsa 1.1.0

7 of the 23 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
perl@5.30.0-9ubuntu0.4
no fix listed
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
perl@5.26.1-6ubuntu0.6
no fix listed
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
perl@5.36.0-7
5.36.0-7+deb12u3
socialmediamacroscope/image_crawler:0.1.2f508216be63c
perl@5.26.1-6ubuntu0.6
no fix listed
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
perl@5.36.0-7
5.36.0-7+deb12u3
socialmediamacroscope/preprocessing:0.1.3ca863306314b
perl@5.36.0-7
5.36.0-7+deb12u3
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

109,485
neosyncneosyncVerified publisher0.5.412 of 3See more

neosync neosync 0.5.41

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

7,056
apineosync-apiVerified publisher0.5.411 of 1See more

api neosync-api 0.5.41

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

2,755
workerneosync-workerVerified publisher0.5.411 of 1See more

worker neosync-worker 0.5.41

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

2,732
netbirdnetbird1.9.01 of 4See more

netbird netbird 1.9.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

6,367
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

7,413
nfl-walletnfl-walletVerified publisher0.1.31 of 4See more

nfl-wallet nfl-wallet 0.1.3

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
perl@0:1.28-423.el8_10
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-3.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

13,047
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,731
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,731
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,510
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

9,831
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

22,713
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

13,331
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

13,405
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

13,387
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
perl@5.18.2-2ubuntu1
no fix listed

Open the chart page →

41,455
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
perl@5.26.1-6ubuntu0.5
no fix listed
linuxserver/codimd:latestb801bbcf6386
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

27,486
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

27,667
firecrawlobeoneVerified publisher3.0.31 of 5See more

firecrawl obeone 3.0.3

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

9,895

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
federid/webhook:0.1.0fbfb7c6510a7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
felipecs8/app-db-connection-test:v129e06c9c6385
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
firefart/requesttracker:5.0.40d6249906d8c
perl@5.36.0-7
5.36.0-7+deb12u3
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
perl@5.30.0-9ubuntu0.5
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
flanksource/apm-hub:v0.0.471dacc3195bf9
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
flyway/flyway:9.1545b5d7cdc75a
perl@5.30.0-9ubuntu0.3
no fix listed
1
fnzv/dump1090:latestb3079b95c336
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
foldingathome/fah-gpu:latest5ef7742d1eb4
perl@5.26.1-6ubuntu0.5
no fix listed
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
perl@5.26.1-6ubuntu0.3
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
perl@5.26.1-6ubuntu0.3
no fix listed
1
free5gmano/nextepc-mongodb:latest36f806935519
perl@5.22.1-9ubuntu0.6
no fix listed
1
freedom98/flask:k3.0d7ce1533f297
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
galaxy/cloudman-server:lateste5c265fe9fcd
perl@5.30.0-9ubuntu0.2
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
perl@5.18.2-2ubuntu1.4
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
perl@5.18.2-2ubuntu1.4
no fix listed
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
gchq/accumulo:2.0.1c460bb587d6d
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
perl@5.26.1-6ubuntu0.7
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
perl@5.26.1-6ubuntu0.3
no fix listed
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
perl@5.30.0-9ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
perl@5.30.0-9ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
perl@5.30.0-9ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
perl@5.30.0-9ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
perl@5.30.0-9ubuntu0.2
no fix listed
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
perl@5.30.0-9ubuntu0.2
no fix listed
1
gethue/hue:4.11.011b649636e68
perl@5.30.0-9ubuntu0.3
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
perl@5.26.1-6ubuntu0.5
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
getsentry/relay:24.10.0ba7bf9163219
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
perl@5.30.0-9ubuntu0.2
no fix listed
1
glasskube/operator:0.12.2be5133100d63
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
perl@5.36.0-7
5.36.0-7+deb12u3
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
perl@5.36.0-7
5.36.0-7+deb12u3
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
perl@5.36.0-7
5.36.0-7+deb12u3
1
gopinatht/ovs-plugin-installer:latest632cb2e9c399
perl@5.22.1-9ubuntu0.3
no fix listed
1
gotson/komga:0.99.49b15ea6bfc30
perl@5.26.1-6ubuntu0.3
no fix listed
1
gradiant/open5gs-dbctl:0.10.3332031245fce
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.2
1
grafana/agent:v0.44.23364714a2f64
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
grafana/alloy:v1.5.101a63f4e032c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
grafana/alloy:v1.4.306bdcbb51fc2
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
grafana/beyla:1.3.336d07f8d276e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
grafana/fluent-plugin-loki:latest8a3882e8c28b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
grafana/promtail:3.5.165bfae480b57
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
graphprotocol/graph-node:latestb0436347fb24
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
graphprotocol/graph-node:v0.37.0f4452cdedd68
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
graylog/graylog:6.1.1019de1aff48c2
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.