StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
kron-aapm-agentkron-aapm-agent1.1.01 of 1See more

kron-aapm-agent kron-aapm-agent 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.1.07feef7d2ab42
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

8,922
adventureworkskronkltdVerified publisher0.1.01 of 1See more

adventureworks kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
chriseaton/adventureworks:latest54c3384ce701
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5

Open the chart page →

4,462
fileserverkronkltdVerified publisher0.3.101 of 1See more

fileserver kronkltd 0.3.10

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
duck1123/lnd-fileserver:latest9d6fb247b714
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

3,769
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
duck1123/cert-downloader:latest0e29f19fa67c
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

5,644
chaos-meshkubeblocksVerified publisher2.7.22 of 4See more

chaos-mesh kubeblocks 2.7.2

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

13,517
ciliumkubeblocksVerified publisher1.15.11 of 2See more

cilium kubeblocks 1.15.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.15.1351d6685dc6f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

5,114
nvidia-gpu-exporterkubeblocksVerified publisher0.3.11 of 1See more

nvidia-gpu-exporter kubeblocks 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,500
openebskubeblocksVerified publisher3.10.02 of 3See more

openebs kubeblocks 3.10.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
openebs/node-disk-operator:2.1.06afe2123c457
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

10,568
spiderpoolkubeblocksVerified publisher1.2.02 of 4See more

spiderpool kubeblocks 1.2.0

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
perl@5.30.0-9ubuntu0.5
no fix listed
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

8,457
juicefs-tenantkubegems1.0.11 of 3See more

juicefs-tenant kubegems 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kubegems/redis:7.2.5-debian-12-r2870ee3a77add
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,120
kube-janitorkube-janitor0.3.31 of 1See more

kube-janitor kube-janitor 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hjacobs/kube-janitor:23.7.0fbb303ed463c
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

3,700
apm-serverkube-opsVerified publisher0.1.21 of 1See more

apm-server kube-ops 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
elastic/apm-server:7.17.6c7a1c63257d0
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,196
kube-ovnkube-ovn-test1.14.01 of 1See more

kube-ovn kube-ovn-test 1.14.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kubeovn/kube-ovn:v1.14.06722b54eb5c0
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

4,991
kube-httpcachekubernetes-replicator0.9.11 of 1See more

kube-httpcache kubernetes-replicator 0.9.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-httpcache:stable2169032c5840
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

4,118
kube-mailkubernetes-replicator0.11.11 of 3See more

kube-mail kubernetes-replicator 0.11.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-mail:latest04f1099241fc
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

2,444
databend-metakubesphere-stable0.7.31 of 1See more

databend-meta kubesphere-stable 0.7.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,448
databend-querykubesphere-stable0.8.31 of 1See more

databend-query kubesphere-stable 0.8.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
datafuselabs/databend-query:v1.2.279a936843b85b4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,448
deepflowkubesphere-stable6.2.6062 of 8See more

deepflow kubesphere-stable 6.2.606

2 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
perl@5.30.0-9ubuntu0.2
no fix listed
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

18,394
iomeshkubesphere-stable1.1.04 of 25See more

iomesh kubesphere-stable 1.1.0

4 of the 25 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.7.25d3f9bf9240b
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
iomesh/node-disk-exporter:1.8.0f03148764f38
perl@5.30.0-9ubuntu0.2
no fix listed
iomesh/node-disk-manager:1.8.0002c4b92fd34
perl@5.30.0-9ubuntu0.2
no fix listed
iomesh/node-disk-operator:1.8.0f6c76380db34
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

48,833
IOMeshkubesphere-stable1.2.04 of 25See more

IOMesh kubesphere-stable 1.2.0

4 of the 25 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.8.01a151f602451
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
iomesh/node-disk-exporter:1.8.0f03148764f38
perl@5.30.0-9ubuntu0.2
no fix listed
iomesh/node-disk-manager:1.8.0-2292ad270082e
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

46,507
pulsarkubesphere-stable2.7.131 of 3See more

pulsar kubesphere-stable 2.7.13

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

14,368
clickhousekubesphere-testVerified publisher0.1.11 of 2See more

clickhouse kubesphere-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

6,701
csi-neonsankubesphere-testVerified publisher1.3.01 of 6See more

csi-neonsan kubesphere-test 1.3.0

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
csiplugin/csi-neonsan:v1.2.21fa83d45417f
perl@5.22.1-9ubuntu0.9
no fix listed

Open the chart page →

18,482
mongodbkubesphere-testVerified publisher0.3.21 of 2See more

mongodb kubesphere-test 0.3.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:4.2.16ca49afbcb2b
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

9,628
mysqlkubesphere-testVerified publisher1.0.21 of 3See more

mysql kubesphere-test 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,381
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

9,384
xenondbkubesphere-testVerified publisher1.0.01 of 3See more

xenondb kubesphere-test 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,381
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
penpotapp/exporter:2.2.15c835ffd87ab
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

17,002
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.42 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

2 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

20,299
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,460
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

6,879
sample-operatorkusionstackVerified publisher0.1.21 of 1See more

sample-operator kusionstack 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
chaerr/kridge:demo-operator-v0.1.266833deec017
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

2,501
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

3,143
keycloak-application-platform-configkvalitetsitVerified publisher0.0.291 of 1See more

keycloak-application-platform-config kvalitetsit 0.0.29

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

3,373
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

16,537
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

7,842
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

26,371
pageslatif-pages1.0.02 of 3See more

pages latif-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
pageslavanya-pages1.0.02 of 3See more

pages lavanya-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

4,270
owntracks-exporterleprechaun-charts0.1.111 of 1See more

owntracks-exporter leprechaun-charts 0.1.11

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

3,448
jackettlib42Verified publisher1.1.01 of 1See more

jackett lib42 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
lib42/jackett:latesta55596cda383
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,632
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,456
lightlyticslightlytics0.1.212 of 2See more

lightlytics lightlytics 0.1.21

2 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,130
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

37,518
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

10,773
pagesliviu884422-pages1.0.02 of 3See more

pages liviu884422-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
locustio/locust:2.24.151d866285170
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,516
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

6,674
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,970

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
perl@5.30.0-9ubuntu0.3
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/dask/dask:2024.1.0080150de7d86
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
perl@5.26.1-6ubuntu0.5
no fix listed
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
perl@5.30.0-9ubuntu0.3
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/hypolia/kanri:0.1.2-rc4fa7d5cc7fb7d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
perl@0:5.74-480.el9
0:5.74-481.1.el9_6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.