StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,262
of 17,781 indexed, latest versions
Container images
1,319
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,262 of 17,781 indexed charts deploy, on 1,319 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,293
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,262 by stars
ChartLatestAffected imagesRadar Score
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

9,412
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

6,908
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

6,297
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
kuzwolka/aws9:news3e8880fbbb96
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
kuzwolka/aws9:blog4a7707410bf1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
kuzwolka/aws9:shop84a9d9766345
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

18,344
azp-agentazp-agent1.2.01 of 1See more

azp-agent azp-agent 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
cheveo/azp-agent:1.0.282240f890884
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

3,268
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

6,297
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
perl@5.30.0-9ubuntu0.2
no fix listed
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
perl@5.30.0-9ubuntu0.2
no fix listed
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

20,671
pagesberrutig-pages1.0.02 of 3See more

pages berrutig-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,190
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

7,190
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

7,956
mx-notifierbicarus-labs1.1.91 of 1See more

mx-notifier bicarus-labs 1.1.9

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bicarus/mx-notifier:1.1.8bed688d16762
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

3,722
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

22,891
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

10,145
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

13,459
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

15,253
istio-bookinfobookinfo1.2.23 of 6See more

istio-bookinfo bookinfo 1.2.2

3 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.15.040e8aba77c1b
perl@5.22.1-9ubuntu0.6
no fix listed
istio/examples-bookinfo-reviews-v2:1.15.0e86d247b7ac2
perl@5.22.1-9ubuntu0.6
no fix listed
istio/examples-bookinfo-reviews-v3:1.15.0e454cab754cf
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

18,980
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
sysnet4admin/colosseum-prm:log5802bfcd7fed
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

26,996
csi-driver-nfsbook-k8sinfra-v24.12.11 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

6,220
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
library/cassandra:3.11.65aa8400b4b3b
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

19,229
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

8,323
pagesbrian-pages1.0.02 of 3See more

pages brian-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,190
pagesbrixton-mayuribhavsar23-pages1.0.02 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,190
pagesbrixton-pages1.0.02 of 3See more

pages brixton-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,190
ombibryanalves0.4.01 of 1See more

ombi bryanalves 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

10,776
plexbryanalves0.5.01 of 1See more

plex bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

6,707
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

14,352
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,869
duoauthproxy-radius-simplecaerus0.1.01 of 1See more

duoauthproxy-radius-simple caerus 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

2,974
ct-singlecalltelemetry0.8.41 of 7See more

ct-single calltelemetry 0.8.4

1 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
calltelemetry/web:0.8.1-rc7205d13269e350
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

10,629
pagescamden-pages1.0.02 of 3See more

pages camden-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,190
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

8,001
geoservercamptocamp20.0.37 of 12See more

geoserver camptocamp2 0.0.3

7 of the 12 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
perl@5.30.0-9ubuntu0.2
no fix listed
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
perl@5.30.0-9ubuntu0.2
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
perl@5.30.0-9ubuntu0.2
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
perl@5.30.0-9ubuntu0.2
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
perl@5.30.0-9ubuntu0.2
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
perl@5.30.0-9ubuntu0.2
no fix listed
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

88,335
httpd-ldapauth-proxycamptocamp31.0.21 of 1See more

httpd-ldapauth-proxy camptocamp3 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/httpd:2.4.631ae8051591a5
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

3,311
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,039
prometheus-puppetdb-sdcamptocamp38.0.21 of 2See more

prometheus-puppetdb-sd camptocamp3 8.0.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
puppet/puppet-agent:7.14.00b6fd9a6b7da
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

6,143
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

5,886
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

10,776
pagescarina-pages1.0.02 of 3See more

pages carina-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,190
pagescarmel-pages-dell1.0.02 of 3See more

pages carmel-pages-dell 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,190
cassandra-clustercassandra-clusterVerified publisher0.1.01 of 1See more

cassandra-cluster cassandra-cluster 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/cassandra:3.11.10b095ff3248c6
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

9,473
opencvecfi20170.1.21 of 7See more

opencve cfi2017 0.1.2

1 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

15,371
clechaosnative0.2.71 of 6See more

cle chaosnative 0.2.7

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
litmuschaos/mongo:4.2.899961210d467
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

16,389
helioscharonVerified publisher0.1.51 of 1See more

helios charon 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
obolnetwork/helios:e10e753cb7e97d39d46
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

2,087
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,778
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

12,779
chat-searchchat-searchVerified publisher0.1.71 of 1See more

chat-search chat-search 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/hemslo/chat-search:latest39d48995a5bd
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,042
opensipschetan-opensips0.1.01 of 1See more

opensips chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
chetangautamm/repo:Opensips_Buildb4b94155ff5a
perl@5.18.2-2ubuntu1.7
no fix listed

Open the chart page →

30,140
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

12,483
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

5,904
basechronicleVerified publisher0.0.81 of 1See more

base chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

4,810

Container images carrying it

1,319 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
perl@5.30.0-9ubuntu0.2
no fix listed
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
kennethreitz/httpbin:latest599fe5e50731
perl@5.26.1-6ubuntu0.2
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
perl@5.30.0-9ubuntu0.3
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
knspar/phronetis:0.1.4609499d2dc91a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
knspar/phronetis-operator:0.1.60c4f0543ee58
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
kong/httpbin:latesta6ac46531193
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
kong/kong:3.9.16addf50e6bd8
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
perl@5.30.0-9ubuntu0.3
no fix listed
1
kserve/models-web-app:v0.13.073486345a602
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
kubeflownotebookswg/jupyter-web-app:v1.9.2afb52057c997
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
kubeflownotebookswg/tensorboards-web-app:v1.9.277f07f52a84a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
perl@5.26.1-6ubuntu0.3
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
perl@5.22.1-9ubuntu0.6
no fix listed
1
kudobuilder/controller:v0.9.069072d979708
perl@5.26.1-6ubuntu0.3
no fix listed
1
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
perl@5.30.0-9ubuntu0.5
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
kuzwolka/aws9:main1ad759b961b1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
kuzwolka/aws9:news3e8880fbbb96
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
kuzwolka/aws9:blog4a7707410bf1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
kuzwolka/aws9:shop84a9d9766345
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
laly9999/node-app:1dd0e503913e1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
langgenius/dify-api:1.0.0066035f93856
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
langgenius/dify-api:0.6.11fca918260dd6
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
lib42/jackett:latesta55596cda383
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
library/cassandra:3.11.10b095ff3248c6
perl@5.30.0-9ubuntu0.2
no fix listed
1
library/couchdb:3.4.22817ad50b5c5
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
library/debian:12.5-slim67f3931ad8cb
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
library/elasticsearch:8.17.32cc40b15dff8
perl@5.30.0-9ubuntu0.5
no fix listed
1
library/elasticsearch:8.15.0310b9fc03b06
perl@5.30.0-9ubuntu0.5
no fix listed
1
library/elasticsearch:7.17.0332c6d416808
perl@5.30.0-9ubuntu0.2
no fix listed
1
library/elasticsearch:7.17.1588c2ec10c7f2
perl@5.30.0-9ubuntu0.5
no fix listed
1
library/elasticsearch:7.17.8fdc73b3249c1
perl@5.30.0-9ubuntu0.3
no fix listed
1
library/flink:1.14.6-scala_2.122461f02672b3
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
library/ghost:5.79.083f7bf209844
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
library/haproxy:3.1-bookworm49a0a0d6f0b8
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
library/haproxy:2.9.6fc5748ff7c72
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
library/httpd:2.4.631ae8051591a5
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
library/kibana:7.17.150172f1c538e7
perl@5.30.0-9ubuntu0.5
no fix listed
1
library/kibana:8.18.004c0fc150f3a
perl@5.30.0-9ubuntu0.5
no fix listed
1
library/kibana:7.17.8c5781ba340ef
perl@5.30.0-9ubuntu0.3
no fix listed
1
library/kibana:7.17.3e2e2031c15be
perl@5.30.0-9ubuntu0.2
no fix listed
1
library/logstash:7.17.817a4f64e9cf5
perl@5.30.0-9ubuntu0.3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.