StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

10,857
giteawenerme12.7.03 of 4See more

gitea wenerme 12.7.0

3 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

8,842
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

8,824
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

15,287
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
openebs/node-disk-operator:2.1.06afe2123c457
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

10,568
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.7.45f2a56b95266
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

14,618
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

9,296
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

7,643
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

6,323
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,548
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

14,172
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

11,592
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,685
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
hamzaarshad10/querypodpy:1.7154f38e8668e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
murtazashah46/helmfile:latest4d11726cf803
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

13,197
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

2,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,674
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
perl@5.26.1-6ubuntu0.5
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

9,250

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
merlos/zookeeper:3.9.3a38fc7e09ed7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
middlewareeng/middleware:0.3.1747d880812f1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
milvusdb/milvus:v2.2.13a3a55e1c1497
perl@5.30.0-9ubuntu0.2
no fix listed
1
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
perl@5.30.0-9ubuntu0.2
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
miqm/session-scaler:0.1.0c5c211717d9b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
mlikiowa/napcat-docker:latest1336a777f9a4
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
moreillon/api-proxy:latestd7d4a5463525
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
moreillon/camera-viewer:lateste418cc694bd5
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
moreillon/food-manager:lateste8fd856e593d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
moreillon/user-manager-front:v5.1.06597e6b98d21
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
perl@5.36.0-7
5.36.0-7+deb12u3
1
mshanley80/httpbin2022:latest5b189a70c0fb
perl@5.30.0-9ubuntu0.3
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
muluder/prograncontrollermcord:0.1.843b597a93da7
perl@5.22.1-9ubuntu0.2
no fix listed
1
murtazashah46/helmfile:latest4d11726cf803
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
mvance/unbound:1.20.04bf67b567f39
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
mvance/unbound:1.22.076906da36d18
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
netbirdio/management:0.45.10c9994b393ea
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
netbirdio/management:0.46.0b0adc4ad4ec6
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
netboxcommunity/netbox:v3.2.83d652dca5351
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
nethermind/nethermind:1.14.615517708c3b6
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
nethermind/nethermind:1.31.893e57917371a
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.2
1
nethermind/nethermind:1.31.9aeca3b55bda5
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.2
1
netrisai/controller-grpc:4.6.0.00753178bf173c2
perl@5.30.0-9ubuntu0.5
no fix listed
1
netrisai/controller-telescope:4.6.0.00414d82948a8b2
perl@5.30.0-9ubuntu0.5
no fix listed
1
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
perl@5.30.0-9ubuntu0.5
no fix listed
1
netrisai/controller-web-session-generator:0.2.0a030a31289f4
perl@5.30.0-9ubuntu0.2
no fix listed
1
networkboot/dhcpd:lateste99bbfbd6fb2
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
perl@5.22.1-9ubuntu0.5
no fix listed
1
nirmalnaveen/supermario:latest8541a39162f3
perl@5.36.0-7
5.36.0-7+deb12u3
1
nvidia/dcgm-exporter:2.2.9-2.4.1-ubuntu20.0491b20b66d1cd
perl@5.30.0-9ubuntu0.2
no fix listed
1
nvidia/k8s-device-plugin:v0.9.0964847cc3fd8
perl@5.22.1-9ubuntu0.9
no fix listed
1
obolnetwork/helios:e10e753cb7e97d39d46
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
oled01/automx2:2025.1.105d3e398e675
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
oled01/db-backup:0.1.06302fd2b5333
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
omecproject/c3po-hss:master-latest638671ef4842
perl@5.22.1-9ubuntu0.9
no fix listed
1
omecproject/c3po-hssdb:master-latest28a90cc26716
perl@5.30.0-9ubuntu0.2
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
perl@5.26.1-6ubuntu0.3
no fix listed
1
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
perl@5.26.1-6ubuntu0.3
no fix listed
1
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
perl@5.26.1-6ubuntu0.5
no fix listed
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
perl@5.26.1-6ubuntu0.3
no fix listed
1
omecproject/ngic-cp:central-cp-multi-upfs-latest24a389a0a4fe
perl@5.26.1-6ubuntu0.3
no fix listed
1
omecproject/onos-progran:1.0.05715e5648aa0
perl@5.22.1-9ubuntu0.2
no fix listed
1
omecproject/openmme:master-latest64776cb9edb3
perl@5.22.1-9ubuntu0.6
no fix listed
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
perl@5.22.1-9ubuntu0.6
no fix listed
1
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
omkara25/simple-microservice-app-user-service:v2d62cba548580
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.