StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
harp-proxyharp0.8.11 of 1See more

harp-proxy harp 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
makersquad/harp-proxy:0.8.1a40dd258c527
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

6,092
hawkhawk1.1.52 of 4See more

hawk hawk 1.1.5

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

13,656
clickstackhdx-oss-v21.1.11 of 5See more

clickstack hdx-oss-v2 1.1.1

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:5.0.32-focal3b6c281e1c08
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

4,750
guacamolehelmforgeVerified publisher1.5.22 of 5See more

guacamole helmforge 1.5.2

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
library/postgres:17.5-bookwormfbcea1bd13b6
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

8,773
helmuphelmupVerified publisher0.1.03 of 3See more

helmup helmup 0.1.0

3 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
sirrend/helmup-notifications-service:0.1.3997866417011
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

16,532
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

4,339
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5

Open the chart page →

12,461
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

15,749
valkey-clusterinnagoVerified publisher1.1.01 of 2See more

valkey-cluster innago 1.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
valkey/valkey:8.0.1c5d4f082b76d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,634
elasticinseefrlab2.2.02 of 2See more

elastic inseefrlab 2.2.0

2 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
perl@5.30.0-9ubuntu0.2
no fix listed
library/kibana:7.17.3e2e2031c15be
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

17,365
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,415
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,489
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,435
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,435
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

10,716
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,393
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
kafkakraft/kafka-controller:3.7.0f261ad288fce
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
kafkakraft/kafkakraft:3.7.02e4b593b878b
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

14,250
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

5,795
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,234
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

5,302
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
langgenius/dify-sandbox:0.2.009b7e8705673
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

20,424
pgbouncerkubernetes-helm-chart-pgbouncer1.0.151 of 1See more

pgbouncer kubernetes-helm-chart-pgbouncer 1.0.15

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
cradlepoint/pgbouncer:1.0.18f5720b0cd03
perl@5.26.1-6ubuntu0.2
no fix listed

Open the chart page →

5,808
kubeseal-webguikubeseal-webgui6.0.41 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

4,101
kubesendkubesend0.1.91 of 1See more

kubesend kubesend 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
v3xl/kubesend:0.1.06f62ca96be82
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

1,385
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,749
kuma-ingress-watcherkuma-ingress-watcherVerified publisher1.4.01 of 1See more

kuma-ingress-watcher kuma-ingress-watcher 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,668
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

12,477
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

114,025
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

35,058
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,456
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

7,915
clickhouseliwenhe1.0.11 of 3See more

clickhouse liwenhe 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.14ccf9c2b5e3f2
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

6,766
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,763
voice-biometricslumenvox2.0.112 of 26See more

voice-biometrics lumenvox 2.0.1

12 of the 26 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-assure-identity:2.0.0147854a3c916
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-audit:2.0.079428add7f38
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-binary-storage:2.0.053decadc102d
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-deployment:2.0.0ea8110886d38
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-management-api:2.0.0b9a23345eabd
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-reporting:2.0.07a9ffdc2178a
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
perl@5.30.0-9ubuntu0.2
no fix listed
lumenvox/cloud-voice-verifier:2.0.014170ad34903
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

71,216
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,741
magentomagento3.2.32 of 12See more

magento magento 3.2.3

2 of the 12 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
perl@5.30.0-9ubuntu0.5
no fix listed
library/rabbitmq:4.1.0-management935b3f84c1e4
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

13,582
maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,014
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

19,192
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

4,184
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

13,763
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

3,729
clowder2ncsaVerified publisher1.9.72 of 12See more

clowder2 ncsa 1.9.7

2 of the 12 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

37,441
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mariadb:10.8.2-focal490f01279be1
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

14,324
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,051
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
perl@5.36.0-7
5.36.0-7+deb12u3
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

14,862
dhcp-serveropencord1.0.21 of 1See more

dhcp-server opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
networkboot/dhcpd:lateste99bbfbd6fb2
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

4,205
librechatopenshift1.9.01 of 3See more

librechat openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,833
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

6,899
opikopikOfficialVerified publisher2.2.611 of 13See more

opik opik 2.2.61

1 of the 13 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.2.0-v10e44b2b49d059
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

14,422
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresqldigest-pinned926356130b77
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

8,510

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
wolveix/satisfactory-server:v1.9.1199be1064b18
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
wolveix/satisfactory-server:v1.9.9464d11e36e10
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
woojoong/wowza:latestec230db19652
perl@5.26.1-6ubuntu0.2
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
xeladock/mysql_dns:latest4baf531453f1
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
xeladock/nginx2:latestc259a67b1dff
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
xeotek/kadeck:4.2.94c6b04d9ce55
perl@5.30.0-9ubuntu0.3
no fix listed
1
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
perl@5.22.1-9ubuntu0.9
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
yandex/clickhouse-client:21.3863f94a0f607
perl@5.26.1-6ubuntu0.5
no fix listed
1
yandex/clickhouse-server:latest1cbf75aabe1e
perl@5.30.0-9ubuntu0.2
no fix listed
1
yandex/clickhouse-server:21.3.204eccfffb01d7
perl@5.30.0-9ubuntu0.2
no fix listed
1
yandex/clickhouse-server:19.17ab1738a64b70
perl@5.26.1-6ubuntu0.3
no fix listed
1
yandex/clickhouse-server:19.14ccf9c2b5e3f2
perl@5.26.1-6ubuntu0.3
no fix listed
1
yandex/clickhouse-server:19.16d210dc69321e
perl@5.26.1-6ubuntu0.3
no fix listed
1
youkadev/api-snap:0.1.14db0f9428e67
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
perl@5.30.0-9ubuntu0.2
no fix listed
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
perl@5.30.0-9ubuntu0.2
no fix listed
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
perl@5.30.0-9ubuntu0.2
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
gcr.io/abacus-labs-dev/hyperlane-agent:10c0ab1-20231215-220639f33e88324a40
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
perl@5.26.1-6ubuntu0.3
no fix listed
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
perl@5.22.1-9
no fix listed
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
perl@5.22.1-9
no fix listed
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
perl@5.22.1-9ubuntu0.6
no fix listed
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
perl@5.30.0-9ubuntu0.2
no fix listed
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
perl@5.22.1-9ubuntu0.6
no fix listed
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
perl@5.30.0-9ubuntu0.2
no fix listed
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
perl@5.22.1-9ubuntu0.6
no fix listed
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
perl@5.30.0-9ubuntu0.5
no fix listed
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
gcr.io/tfx-oss-public/ml_metadata_store_server:1.14.051404ef4419c
perl@5.30.0-9ubuntu0.3
no fix listed
1
gcr.io/tfx-oss-public/ml_metadata_store_server:1.5.0db8691752b4c
perl@5.26.1-6ubuntu0.5
no fix listed
1
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
perl@5.26.1-6ubuntu0.7
no fix listed
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.