StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
harp-proxyharp0.8.11 of 1See more

harp-proxy harp 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
makersquad/harp-proxy:0.8.1a40dd258c527
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

6,092
hawkhawk1.1.52 of 4See more

hawk hawk 1.1.5

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

13,656
clickstackhdx-oss-v21.1.11 of 5See more

clickstack hdx-oss-v2 1.1.1

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:5.0.32-focal3b6c281e1c08
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

4,750
guacamolehelmforgeVerified publisher1.5.22 of 5See more

guacamole helmforge 1.5.2

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
library/postgres:17.5-bookwormfbcea1bd13b6
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

8,773
helmuphelmupVerified publisher0.1.03 of 3See more

helmup helmup 0.1.0

3 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
sirrend/helmup-notifications-service:0.1.3997866417011
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

16,532
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

4,339
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5

Open the chart page →

12,461
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

15,749
valkey-clusterinnagoVerified publisher1.1.01 of 2See more

valkey-cluster innago 1.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
valkey/valkey:8.0.1c5d4f082b76d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,634
elasticinseefrlab2.2.02 of 2See more

elastic inseefrlab 2.2.0

2 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
perl@5.30.0-9ubuntu0.2
no fix listed
library/kibana:7.17.3e2e2031c15be
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

17,365
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,415
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,489
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,435
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,435
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,716
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,393
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
kafkakraft/kafka-controller:3.7.0f261ad288fce
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
kafkakraft/kafkakraft:3.7.02e4b593b878b
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

14,250
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

5,795
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,234
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

5,302
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
langgenius/dify-sandbox:0.2.009b7e8705673
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

20,424
pgbouncerkubernetes-helm-chart-pgbouncer1.0.151 of 1See more

pgbouncer kubernetes-helm-chart-pgbouncer 1.0.15

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
cradlepoint/pgbouncer:1.0.18f5720b0cd03
perl@5.26.1-6ubuntu0.2
no fix listed

Open the chart page →

5,808
kubeseal-webguikubeseal-webgui6.0.41 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

4,101
kubesendkubesend0.1.91 of 1See more

kubesend kubesend 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
v3xl/kubesend:0.1.06f62ca96be82
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

1,385
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,749
kuma-ingress-watcherkuma-ingress-watcherVerified publisher1.4.01 of 1See more

kuma-ingress-watcher kuma-ingress-watcher 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,668
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

12,477
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

114,025
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

35,058
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,456
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

7,915
clickhouseliwenhe1.0.11 of 3See more

clickhouse liwenhe 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.14ccf9c2b5e3f2
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

6,766
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,763
voice-biometricslumenvox2.0.112 of 26See more

voice-biometrics lumenvox 2.0.1

12 of the 26 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-assure-identity:2.0.0147854a3c916
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-audit:2.0.079428add7f38
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-binary-storage:2.0.053decadc102d
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-deployment:2.0.0ea8110886d38
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-management-api:2.0.0b9a23345eabd
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-reporting:2.0.07a9ffdc2178a
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-voice-verifier:2.0.014170ad34903
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

71,216
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,741
magentomagento3.2.32 of 12See more

magento magento 3.2.3

2 of the 12 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
perl@5.30.0-9ubuntu0.5
no fix listed
library/rabbitmq:4.1.0-management935b3f84c1e4
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

13,582
maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,014
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

19,192
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

4,184
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

13,763
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

3,729
clowder2ncsaVerified publisher1.9.72 of 12See more

clowder2 ncsa 1.9.7

2 of the 12 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

37,441
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mariadb:10.8.2-focal490f01279be1
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

14,324
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,051
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
perl@5.36.0-7
5.36.0-7+deb12u3
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

14,862
dhcp-serveropencord1.0.21 of 1See more

dhcp-server opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
networkboot/dhcpd:lateste99bbfbd6fb2
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

4,205
librechatopenshift1.9.01 of 3See more

librechat openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,833
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

6,899
opikopikOfficialVerified publisher2.2.611 of 13See more

opik opik 2.2.61

1 of the 13 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.2.0-v10e44b2b49d059
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

14,422
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresqldigest-pinned926356130b77
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

8,510

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
spy86/rabbitmq-stomp:latestea649101b9fb
perl@5.30.0-9ubuntu0.3
no fix listed
1
stackstorm/st2actionrunner:3.888235ba70cad
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2api:3.86f56d239d280
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2auth:3.833ecfda16608
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2notifier:3.8f190a6212195
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2rulesengine:3.8259503496ff9
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2scheduler:3.8b1de2055c362
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2stream:3.81c8904a3bf67
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2timersengine:3.81bf35bfaf00c
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2web:3.809989a26c8b7
perl@5.30.0-9ubuntu0.5
no fix listed
1
stackstorm/st2workflowengine:3.819fdfffdbba8
perl@5.30.0-9ubuntu0.5
no fix listed
1
stashapp/stash:latest24dbd7607174
perl@5.30.0-9ubuntu0.2
no fix listed
1
stashapp/stash-box:latesta534c8afdf39
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
statcan/ckan:2.93921305425b8
perl@5.30.0-9ubuntu0.2
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
perl@5.30.0-9ubuntu0.2
no fix listed
1
structurizr/onpremises:2025.11.094b5ffb5119c8
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
substratusai/verba:v0.4.0-baseURL261695be635eb
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
supabase/edge-runtime:v1.59.0eff9c554d649
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
supabase/realtime:v2.33.8d207e6e23ad3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
supabase/studio:20241021-9f9b08326d8070c55e9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
perl@5.30.0-9ubuntu0.4
no fix listed
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
perl@5.30.0-9ubuntu0.5
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
tdengine/tdengine:3.0.2.24140a4021ddb
perl@5.26.1-6ubuntu0.6
no fix listed
1
teknas09/bird-pod:latest12a1fa85c4aa
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
perl@5.22.1-9ubuntu0.2
no fix listed
1
testinprod/op-erigon:latest0a125bd77a2d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
thecampagnards/trafficlight-api:main7dca9d973837
perl@5.30.0-9ubuntu0.2
no fix listed
1
theradius/loggia:0.463ba348546ec
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
thesisrobot/bitcoind:v23.016b368e4d52c
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
thmmniii/fbs-core:v1.27.15438517d9fc2
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.