StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,262
of 17,781 indexed, latest versions
Container images
1,319
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,262 of 17,781 indexed charts deploy, on 1,319 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,293
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,262 by stars
ChartLatestAffected imagesRadar Score
giteagiteaOfficialVerified publisher12.7.03 of 4See more

gitea gitea 12.7.0

3 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

8,811
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

6,556
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

11,367
openebsopenebsOfficialVerified publisher4.6.12 of 35See more

openebs openebs 4.6.1

2 of the 35 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.2
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

23,894
apisixapisix2.17.01 of 3See more

apisix apisix 2.17.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

3,045
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
perl@5.26.1-6ubuntu0.6
no fix listed

Open the chart page →

5,552
openldap-stack-hahelm-openldapVerified publisher4.3.31 of 5See more

openldap-stack-ha helm-openldap 4.3.3

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jpgouin/openldap:2.6.9-fixbfdd0088c776
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,919
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

9,145
grafana-agentgrafana0.44.21 of 2See more

grafana-agent grafana 0.44.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
grafana/agent:v0.44.23364714a2f64
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

3,475
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
perl@5.30.0-9ubuntu0.2
no fix listed
milvusdb/milvus:v2.2.13a3a55e1c1497
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

32,259
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

10,622
signozsignoz0.141.11 of 5See more

signoz signoz 0.141.1

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.972aa1e4c1ec5
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,568
weblateweblateOfficialVerified publisher0.5.362 of 3See more

weblate weblate 0.5.36

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/redis:latest5927ff3702df
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

6,699
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,800
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

4,802
difydoubanVerified publisher0.10.02 of 6See more

dify douban 0.10.0

2 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

19,391
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

3,606
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

6,927
stacks-blockchainhirosystemsVerified publisher2.2.21 of 1See more

stacks-blockchain hirosystems 2.2.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

1,374
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
perl@5.22.1-9ubuntu0.6
no fix listed
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

23,964
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

4,154
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.02 of 5See more

openproject openproject-helm-charts 13.11.0

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
openproject/hocuspocus:release-338001b288dc1359dfb5
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

19,926
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

11,384
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

33,725
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

4,293
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

6,543
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

8,364
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

5,987
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
perl@5.30.0-9ubuntu0.5
no fix listed
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

12,746
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

8,390
litellm-helmlitellm1.100.11 of 2See more

litellm-helm litellm 1.100.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,003
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

3,382
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

15,592
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,880
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

11,933
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,352
milvusmilvus-helm5.0.271 of 4See more

milvus milvus-helm 5.0.27

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

10,670
prefect-serverprefectVerified publisher2026.9.32126051 of 2See more

prefect-server prefect 2026.9.3212605

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,786
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

18,509
codefreshcodefresh-onpremOfficialVerified publisher2.12.134 of 42See more

codefresh codefresh-onprem 2.12.13

4 of the 42 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
bitnamilegacy/rabbitmq:4.1.39e635efba431
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

14,956
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2api:3.86f56d239d280
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2auth:3.833ecfda16608
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2notifier:3.8f190a6212195
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2web:3.809989a26c8b7
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

96,419
supabasetokens-studioVerified publisher1.0.05 of 14See more

supabase tokens-studio 1.0.0

5 of the 14 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
supabase/edge-runtime:v1.59.0eff9c554d649
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
supabase/postgres-meta:v0.84.2d0a96973e9f1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
supabase/realtime:v2.33.8d207e6e23ad3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
supabase/studio:20241021-9f9b08326d8070c55e9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

23,123
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

8,493
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

3,454
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

7,857
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,480
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,405
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

4,244
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
5.36.0-7+deb12u3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

32,902
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

3,606

Container images carrying it

1,319 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
guacamole/guacamole:1.5.50f62f6d17ab3
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
gulacedia/web-dvwa-new:v367b467d961ca
perl@5.36.0-7
5.36.0-7+deb12u3
1
hamidyousefi93/saam-test:latestc34f071f6ed0
perl@5.36.0-7
5.36.0-7+deb12u3
1
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hamzaarshad10/querypodpy:1.7154f38e8668e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hansehe/locust:1.1.0bc8e45262bc4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hassroutyyoussef/accountservice:latest1f01edf1ee0c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hassroutyyoussef/orderservice:latest2fc3d1617928
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hassroutyyoussef/userservice:lateste0392e2b4a90
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
haugene/transmission-openvpn:4.0059216cfae4b
perl@5.30.0-9ubuntu0.2
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
perl@5.30.0-9ubuntu0.2
no fix listed
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
perl@5.30.0-9ubuntu0.2
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
perl@5.30.0-9ubuntu0.4
no fix listed
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hazegoodlife/haaze:milksite8d4c63169e14
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
perl@5.30.0-9ubuntu0.5
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
perl@5.36.0-7
5.36.0-7+deb12u3
1
hiboxsystems/marge-bot:0.14.0dcffb926e563
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
perl@5.36.0-7
5.36.0-7+deb12u3
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
perl@5.36.0-7
5.36.0-7+deb12u3
1
hmediade/printserver:latest481a552c8e1c
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
hmediade/printserver-init:latest7f005eb6c718
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
housewrecker/gaps:latestf417dd0a7547
perl@5.30.0-9ubuntu0.2
no fix listed
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
perl@5.26.1-6ubuntu0.5
no fix listed
1
hugohg34/toposervice:0.0.2812a03b3f274
perl@5.30.0-9ubuntu0.2
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
perl@5.22.1-9ubuntu0.5
no fix listed
1
hyperledger/fabric-orderer:1.3.06ee1abcfd840
perl@5.22.1-9ubuntu0.5
no fix listed
1
hyperledger/fabric-peer:1.3.06756c7c48234
perl@5.22.1-9ubuntu0.5
no fix listed
1
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
perl@0:1.28-417.el8_3
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Unicode-Normalize@1.25-396.el8
0:1.28-423.el8_10
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
perl@5.22.1-9ubuntu0.5
no fix listed
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
perl@5.22.1-9ubuntu0.3
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
perl@5.22.1-9ubuntu0.2
no fix listed
1
ibmcom/skydive:0.22.0395e60cc6e3d
perl@5.26.1-6ubuntu0.3
no fix listed
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
perl@5.36.0-7
5.36.0-7+deb12u3
1
improwised/proxysql:master-6b26e59-171765063828940522e8b7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
inseefrlab/shelly:cloudshell31f04ca7436b
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
instructure/kinesalite:latest34400d82f28f
perl@5.30.0-9ubuntu0.5
no fix listed
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
perl@5.30.0-9ubuntu0.2
no fix listed
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
perl@5.30.0-9ubuntu0.2
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
intel/trusted-certificate-issuer:0.5.0591a9db4a427
perl@5.30.0-9ubuntu0.3
no fix listed
1
iofog/router:2.0.17260cf861479
perl@5.26.1-6ubuntu0.3
no fix listed
1
iomesh/csi-driver:v2.8.01a151f602451
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
iomesh/csi-driver:v2.7.25d3f9bf9240b
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
iomesh/node-disk-manager:1.8.0002c4b92fd34
perl@5.30.0-9ubuntu0.2
no fix listed
1
iomesh/node-disk-manager:1.8.0-2292ad270082e
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.