StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
clickhouse-keepersinextraVerified publisher0.7.21 of 1See more

clickhouse-keeper sinextra 0.7.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

2,220
mongosqldsinextraVerified publisher0.3.71 of 1See more

mongosqld sinextra 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5

Open the chart page →

2,599
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

5,894
envoyslamdev0.0.171 of 2See more

envoy slamdev 0.0.17

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.18.2e8b37c1d7578
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

4,705
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

9,235
oi-slurm-cluster-chartslurm-cluster-chart0.25.11 of 4See more

oi-slurm-cluster-chart slurm-cluster-chart 0.25.1

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

4,376
slurm-cluster-chartslurm-cluster-chart0.25.01 of 4See more

slurm-cluster-chart slurm-cluster-chart 0.25.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

4,376
amt-configuresmarthallVerified publisher0.1.11 of 1See more

amt-configure smarthall 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
boxcutter/meshcmd:1.1.384e13f01bcab
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

2,759
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,571
aafsmo-helm-chart6.0.01 of 14See more

aaf smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

25,793
aaismo-helm-chart6.0.01 of 14See more

aai smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

25,827
dgbuildersmo-helm-chart6.0.01 of 3See more

dgbuilder smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
perl@5.22.1-9ubuntu0.2
no fix listed

Open the chart page →

28,494
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

25,793
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

24,800
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
perl@5.22.1-9ubuntu0.2
no fix listed

Open the chart page →

29,244
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

24,800
msbsmo-helm-chart6.0.01 of 6See more

msb smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
perl@5.22.1-9ubuntu0.2
no fix listed

Open the chart page →

27,501
multicloudsmo-helm-chart6.0.01 of 14See more

multicloud smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
perl@5.22.1-9
no fix listed

Open the chart page →

9,442
pndasmo-helm-chart6.0.01 of 3See more

pnda smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
perl@5.22.1-9ubuntu0.2
no fix listed

Open the chart page →

27,501
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
perl@5.22.1-9ubuntu0.2
no fix listed

Open the chart page →

29,244
portalsmo-helm-chart6.0.01 of 8See more

portal smo-helm-chart 6.0.0

1 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
perl@5.22.1-9ubuntu0.2
no fix listed

Open the chart page →

27,501
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

25,793
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

25,793
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

25,793
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

24,800
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

24,800
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

25,793
space-engineerssoblivionscall1.0.21 of 2See more

space-engineers soblivionscall 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/ubuntu:xenial1f1a2d56de1d
perl@5.22.1-9ubuntu0.9
no fix listed

Open the chart page →

2,772
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

13,653
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

13,127
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

30,759
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sashafefler/spacecapybara_app:latestf96d7804c0ca
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

11,243
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

3,272
speckle-preview-service-branch-testing6speckleVerified publisher2.23.14-branch.testing6.334655-b4e04ee1 of 1See more

speckle-preview-service-branch-testing6 speckle 2.23.14-branch.testing6.334655-b4e04ee

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,636
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e12 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

15,684
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb2 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

16,431
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f82 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

14,703
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091142 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

16,431
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4692 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d4694bd113093583
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

14,245
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3412 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.18.12-branch.testing3.88744-f55b3414bd113093583
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

14,245
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b22 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

16,050
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

14,500
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

10,647
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

6,955
envoy-proxysqream-chartsVerified publisher0.6.01 of 2See more

envoy-proxy sqream-charts 0.6.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.1e596fda6a0ce
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

2,309
pagessrinipages1.0.02 of 3See more

pages srinipages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
perl@0:1.28-419.el8_4.1
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.28-423.el8_10
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

28,165
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

18,426
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,854
lighthouse-validatorstakewise7.0.11 of 2See more

lighthouse-validator stakewise 7.0.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sigp/lighthouse:v7.0.12cae720e9a35
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

2,020

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
grpl/grapple-cli:0.2.127c00aafee6629
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
guacamole/guacamole:1.5.50f62f6d17ab3
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
gulacedia/web-dvwa-new:v367b467d961ca
perl@5.36.0-7
5.36.0-7+deb12u3
1
hamidyousefi93/saam-test:latestc34f071f6ed0
perl@5.36.0-7
5.36.0-7+deb12u3
1
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hamzaarshad10/querypodpy:1.7154f38e8668e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hansehe/locust:1.1.0bc8e45262bc4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hassroutyyoussef/accountservice:latest1f01edf1ee0c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hassroutyyoussef/orderservice:latest2fc3d1617928
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hassroutyyoussef/userservice:lateste0392e2b4a90
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
haugene/transmission-openvpn:4.0059216cfae4b
perl@5.30.0-9ubuntu0.2
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
perl@5.30.0-9ubuntu0.2
no fix listed
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
perl@5.30.0-9ubuntu0.2
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
perl@5.30.0-9ubuntu0.4
no fix listed
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hazegoodlife/haaze:milksite8d4c63169e14
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
perl@5.30.0-9ubuntu0.5
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
perl@5.36.0-7
5.36.0-7+deb12u3
1
hiboxsystems/marge-bot:0.14.0dcffb926e563
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
perl@5.36.0-7
5.36.0-7+deb12u3
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
perl@5.36.0-7
5.36.0-7+deb12u3
1
hmediade/printserver:latest481a552c8e1c
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
hmediade/printserver-init:latest7f005eb6c718
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
housewrecker/gaps:latestf417dd0a7547
perl@5.30.0-9ubuntu0.2
no fix listed
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
perl@5.26.1-6ubuntu0.5
no fix listed
1
hugohg34/toposervice:0.0.2812a03b3f274
perl@5.30.0-9ubuntu0.2
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
perl@5.22.1-9ubuntu0.5
no fix listed
1
hyperledger/fabric-orderer:1.3.06ee1abcfd840
perl@5.22.1-9ubuntu0.5
no fix listed
1
hyperledger/fabric-peer:1.3.06756c7c48234
perl@5.22.1-9ubuntu0.5
no fix listed
1
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
perl@0:1.28-417.el8_3
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Unicode-Normalize@1.25-396.el8
0:1.28-423.el8_10
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
perl@5.22.1-9ubuntu0.5
no fix listed
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
perl@5.22.1-9ubuntu0.3
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
perl@5.22.1-9ubuntu0.2
no fix listed
1
ibmcom/skydive:0.22.0395e60cc6e3d
perl@5.26.1-6ubuntu0.3
no fix listed
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
perl@5.36.0-7
5.36.0-7+deb12u3
1
improwised/proxysql:master-6b26e59-171765063828940522e8b7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
inseefrlab/shelly:cloudshell31f04ca7436b
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
instructure/kinesalite:latest34400d82f28f
perl@5.30.0-9ubuntu0.5
no fix listed
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
perl@5.30.0-9ubuntu0.2
no fix listed
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
perl@5.30.0-9ubuntu0.2
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
intel/trusted-certificate-issuer:0.5.0591a9db4a427
perl@5.30.0-9ubuntu0.3
no fix listed
1
iofog/router:2.0.17260cf861479
perl@5.26.1-6ubuntu0.3
no fix listed
1
iomesh/csi-driver:v2.8.01a151f602451
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
iomesh/csi-driver:v2.7.25d3f9bf9240b
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
iomesh/node-disk-manager:1.8.0002c4b92fd34
perl@5.30.0-9ubuntu0.2
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.