StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,790 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,790 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

9,668
teitest-opea1.0.01 of 1See more

tei test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,300
teireranktest-opea1.0.01 of 1See more

teirerank test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,300
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,395
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,368
vehicle-dashboardtest-vehi-dash0.1.02 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
library/mongo:5.0.217c81758cb295
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

20,378
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,980
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

10,159
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

10,071
standard-applicationthebitgram1.0.121 of 1See more

standard-application thebitgram 1.0.12

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
perl@5.22.1-9
no fix listed

Open the chart page →

11,015
trafficlight-apithecampagnards0.1.11 of 1See more

trafficlight-api thecampagnards 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
thecampagnards/trafficlight-api:main7dca9d973837
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,398
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

25,423
pagesthiru-pages1.0.02 of 3See more

pages thiru-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

5,574
todoapitodoapi-appVerified publisher0.1.01 of 2See more

todoapi todoapi-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

6,828
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
perl@0:1.28-419.el8_4.1
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
0:1.28-423.el8_10
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb

Open the chart page →

12,724
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

17,396
altinnendata-apptumogroup0.1.171 of 1See more

altinnendata-app tumogroup 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sondresjo/altinnendata-app:v1.9.1c2707839d8a3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

1,855
bobby-apitumogroup1.0.11 of 1See more

bobby-api tumogroup 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sondresjo/bobby-api:latestfe534731909a
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

2,317
nstuning-apptumogroup0.1.181 of 1See more

nstuning-app tumogroup 0.1.18

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sondresjo/nstuning-app:v1.6.113a6795bf36da
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

1,855
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.2.0-v10e44b2b49d059
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

5,602
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

4,128
umbrella-chartumbrella-chartVerified publisher0.1.13 of 5See more

umbrella-chart umbrella-chart 0.1.1

3 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hassroutyyoussef/accountservice:latest1f01edf1ee0c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
hassroutyyoussef/orderservice:latest2fc3d1617928
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
hassroutyyoussef/userservice:lateste0392e2b4a90
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,512
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

8,642
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,245
opencloudunxwaresVerified publisher0.2.37 of 13See more

opencloud unxwares 0.2.3

7 of the 13 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

45,472
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

15,340
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

14,431
telegram-rebotvcnngrVerified publisher1.0.02 of 3See more

telegram-rebot vcnngr 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
vcnngr/telegram-login:latest1a849a997b6d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
vcnngr/telegram-rebot:latest30f1f05e57a6
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

5,060
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

9,424
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

10,813
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

13,575
pagesvictor-pages1.0.02 of 3See more

pages victor-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
kube-monitoring-telegram-botviento-repository1.0.01 of 1See more

kube-monitoring-telegram-bot viento-repository 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

7,897
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

11,448
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,242
eth-validatorwateim1.4.51 of 3See more

eth-validator wateim 1.4.5

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
wateim/lighthouse-launch:latest2520149ee574
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

5,090
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

6,007
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,171
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

6,282
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,166
wbaas-backupwbstack0.1.01 of 1See more

wbaas-backup wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

9,752
myweatherhelmwebapp11.3.501 of 8See more

myweatherhelm webapp1 1.3.50

1 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

9,252
myweatherhelm-schedulingwebapp11.3.921 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

1 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

9,252
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

10,111
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

14,414
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
perl@5.30.0-9ubuntu0.2
no fix listed
library/mongo:4.44be76f674fc4
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

28,697
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,695
apisixwenerme2.17.01 of 3See more

apisix wenerme 2.17.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

3,118

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
perl@5.30.0-9ubuntu0.3
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/dask/dask:2024.1.0080150de7d86
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
perl@5.26.1-6ubuntu0.5
no fix listed
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
perl@5.30.0-9ubuntu0.3
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/hemslo/chat-search:latest39d48995a5bd
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/huggingface/text-embeddings-inference:cpu-1.666db77d7856c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/hypolia/kanri:0.1.2-rc4fa7d5cc7fb7d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
perl@0:5.74-480.el9
0:5.74-481.1.el9_6
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.