StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
interbtc-parachaininterlay0.4.131 of 1See more

interbtc-parachain interlay 0.4.13

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
interlayhq/interbtc:latesta66d0e35e70f
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,195
interbtc-vaultinterlay0.1.131 of 1See more

interbtc-vault interlay 0.1.13

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
interlayhq/interbtc-clients:vault-masterc3e311de67da
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

3,870
polkabtc-parachaininterlay0.2.411 of 4See more

polkabtc-parachain interlay 0.2.41

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
interlayhq/interbtc:latesta66d0e35e70f
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,937
polkabtc-vaultinterlay0.1.111 of 1See more

polkabtc-vault interlay 0.1.11

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
interlayhq/interbtc-clients:vault-masterc3e311de67da
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

3,870
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

5,570
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

5,570
istio-bookinfoistio-bookinfo1.2.23 of 6See more

istio-bookinfo istio-bookinfo 1.2.2

3 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.15.040e8aba77c1b
perl@5.22.1-9ubuntu0.6
no fix listed
istio/examples-bookinfo-reviews-v2:1.15.0e86d247b7ac2
perl@5.22.1-9ubuntu0.6
no fix listed
istio/examples-bookinfo-reviews-v3:1.15.0e454cab754cf
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

18,998
ztunnelistio-ztunnelVerified publisher1.25.01 of 1See more

ztunnel istio-ztunnel 1.25.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/ztunnel:1.25.005f3972d80a9
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.2

Open the chart page →

2,497
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5

Open the chart page →

3,813
daveit-at-mOfficialVerified publisher0.2.153 of 11See more

dave it-at-m 0.2.15

3 of the 11 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/postgresql:latest42a8200d3597
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

15,245
wjh-rechnerit-at-mOfficialVerified publisher1.0.41 of 1See more

wjh-rechner it-at-m 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
perl@0:5.74-480.el9
0:5.74-481.1.el9_6

Open the chart page →

3,487
opencloudjacobcolvinVerified publisher0.2.37 of 13See more

opencloud jacobcolvin 0.2.3

7 of the 13 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

45,392
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

10,816
jasperjasperVerified publisher1.0.2031 of 2See more

jasper jasper 1.0.203

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

9,148
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

5,066
jellyfinjellyfin-helm10.9.101 of 1See more

jellyfin jellyfin-helm 10.9.10

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.9.1079fb3d73a3e9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,097
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

4,038
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

5,256
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

7,842
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

6,648
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

6,629
image-storage-servicejtektVerified publisher0.4.33 of 4See more

image-storage-service jtekt 0.4.3

3 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

22,665
shinsei-managerjtektVerified publisher0.2.05 of 8See more

shinsei-manager jtekt 0.2.0

5 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
moreillon/user-manager:v5.0.2e1c9bfab5c16
perl@5.36.0-7
5.36.0-7+deb12u3
moreillon/user-manager-front:v5.0.3b067dbbbb6af
perl@5.36.0-7
5.36.0-7+deb12u3
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

59,560
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

16,626
actual-budgetk8s-chartsVerified publisher0.2.31 of 1See more

actual-budget k8s-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
actualbudget/actual-server:25.3.158fecd9088b7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,622
bitcoin-stackk8s-chartsVerified publisher1.0.11 of 1See more

bitcoin-stack k8s-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
blockstream/bitcoind:27.29472492530e3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,425
jellyfink8s-chartsVerified publisher0.2.41 of 1See more

jellyfin k8s-charts 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.696b09723b22f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,116
nostr-rs-relayk8s-chartsVerified publisher1.0.11 of 1See more

nostr-rs-relay k8s-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
scsibug/nostr-rs-relay:0.9.003f54bfbffff
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

3,360
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

6,136
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

8,879
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

9,832
librephotosk8sonlabVerified publisher1.1.62 of 7See more

librephotos k8sonlab 1.1.6

2 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/redis:latest5927ff3702df
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

14,833
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

7,333
k8s-ssh-bastionk8s-ssh-bastion0.5.41 of 1See more

k8s-ssh-bastion k8s-ssh-bastion 0.5.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

3,321
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

7,292
kanrikanri0.1.01 of 1See more

kanri kanri 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/hypolia/kanri:0.1.2-rc4fa7d5cc7fb7d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

1,993
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

16,464
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,599
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,098
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
perl@5.22.1-9ubuntu0.9
no fix listed

Open the chart page →

8,816
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

12,541
phppgadminkfirfer0.1.121 of 1See more

phppgadmin kfirfer 0.1.12

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

10,303
quickwitkfirfer0.7.21 of 1See more

quickwit kfirfer 0.7.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,492
rabbitmqkfirfer0.7.211 of 2See more

rabbitmq kfirfer 0.7.21

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/rabbitmq:3.12.100742852455ad
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

2,484
kiaekiae0.1.61 of 9See more

kiae kiae 0.1.6

1 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/pilot:1.15.2db08d6963975
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

19,208
graphiti-mcpkiberonlabs0.1.21 of 1See more

graphiti-mcp kiberonlabs 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

3,284
cdashkitwareVerified publisher0.19.02 of 3See more

cdash kitware 0.19.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
bitnamilegacy/postgresql:17.2.0-debian-12-r5cf63048c9209
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

12,131
visual-regression-trackerkokuwa5.1.02 of 4See more

visual-regression-tracker kokuwa 5.1.0

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r15fdc6979dbc53
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
visualregressiontracker/api:5.0.11941aeb8c8bf9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

8,680
kovi-appkovi-charts0.8.11 of 1See more

kovi-app kovi-charts 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kennethreitz/httpbin:latest599fe5e50731
perl@5.26.1-6ubuntu0.2
no fix listed

Open the chart page →

14,827
kubeflowkromanow94-kubeflow0.5.19 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

9 of the 30 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kserve/models-web-app:v0.13.073486345a602
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
kubeflownotebookswg/jupyter-web-app:v1.9.2afb52057c997
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
kubeflownotebookswg/tensorboards-web-app:v1.9.277f07f52a84a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
library/python:3.7eedf63967cdb
perl@5.36.0-7
5.36.0-7+deb12u3
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
perl@5.30.0-9ubuntu0.5
no fix listed
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
gcr.io/tfx-oss-public/ml_metadata_store_server:1.14.051404ef4419c
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

68,994

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
onosproject/onos:2.2.144914a8d4b3f
perl@5.26.1-6ubuntu0.3
no fix listed
1
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
perl@5.22.1-9
no fix listed
1
opea/asr:1.025dd26d9cd09
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/chatqna:1.038c51b791efa
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/codegen:1.058f91683892d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/codegen-ui:1.02bee4eb66f3e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/codetrans:1.0e2436483b73d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/codetrans-ui:1.03ef121f34610
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/docsum:1.03eaa91849512
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/docsum-ui:1.07f854e9bffaf
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/guardrails-tgi:1.0262c6048aab8
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/guardrails-tgi:latestf68bec6a1271
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/speecht5:1.0249afad3d268
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/tts:1.0257ae94709e9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opea/web-retriever-chroma:1.0fe08165d7770
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
openbas/caldera-server:5.1.0a277796d9724
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opencsghq/csghub-portal:v2.4.0-ee93ad59164d87
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
opencsghq/kubectl:latestb6d87e1048c2
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
opendatacube/pipelines:wofs-1.225d810e8504b8
perl@5.26.1-6ubuntu0.3
no fix listed
1
opendatacube/restcube:latest91870111837c
perl@5.26.1-6ubuntu0.3
no fix listed
1
opendatacube/wms:latest1b90cdf68831
perl@5.26.1-6ubuntu0.3
no fix listed
1
opendatacube/wps:latest80df355a660b
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
openelevation/open-elevation:latest82fb21612e86
perl@5.30.0-9ubuntu0.2
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
perl@5.30.0-9ubuntu0.2
no fix listed
1
openproject/hocuspocus:release-338001b288dc1359dfb5
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
perl@5.30.0-9ubuntu0.4
no fix listed
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
perl@5.30.0-9ubuntu0.4
no fix listed
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
perl@5.30.0-9ubuntu0.4
no fix listed
1
openthread/otbr:latestf307f59f6432
perl@5.26.1-6ubuntu0.7
no fix listed
1
openvino/model_server:2025.2.11e7cd1d70cc1
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
perl@5.26.1-6ubuntu0.5
no fix listed
1
opsmx11/issuegen:v2.1.05c50ca123d88
perl@5.18.2-2ubuntu1.4
no fix listed
1
outlinewiki/outline:0.82.0494dfb9249a6
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
owncloud/server:10.15.051d9b74fc2a8
perl@5.30.0-9ubuntu0.5
no fix listed
1
oxfordsemantic/rdfox:5.6db17910eb855
perl@5.30.0-9ubuntu0.2
no fix listed
1
oxfordsemantic/rdfox-init:5.6baf570ff968d
perl@5.30.0-9ubuntu0.2
no fix listed
1
pangeo/base-notebook:2024.01.155fbe688a4f80
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
penpotapp/backend:2.2.147853d9bb9dd
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
penpotapp/exporter:2.2.15c835ffd87ab
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
phan2410/dummy-service:0.0.89c6ed6de26ca
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
photoprism/photoprism:220629-jammy2954334adbda
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
photoprism/photoprism:240711-cefc6fd632ca74
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
pk910/powfaucet:v2-stable3dcae6a62896
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
platform9community/admin-server:latestde3fa9b70df1
perl@5.26.1-6ubuntu0.5
no fix listed
1
platform9community/api-gateway:latest40a4970de568
perl@5.26.1-6ubuntu0.5
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.