StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
kron-aapm-agentkron-aapm-agent1.1.01 of 1See more

kron-aapm-agent kron-aapm-agent 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.1.07feef7d2ab42
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

8,922
adventureworkskronkltdVerified publisher0.1.01 of 1See more

adventureworks kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
chriseaton/adventureworks:latest54c3384ce701
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5

Open the chart page →

4,462
fileserverkronkltdVerified publisher0.3.101 of 1See more

fileserver kronkltd 0.3.10

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
duck1123/lnd-fileserver:latest9d6fb247b714
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

3,769
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
duck1123/cert-downloader:latest0e29f19fa67c
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

5,644
chaos-meshkubeblocksVerified publisher2.7.22 of 4See more

chaos-mesh kubeblocks 2.7.2

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

13,517
ciliumkubeblocksVerified publisher1.15.11 of 2See more

cilium kubeblocks 1.15.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.15.1351d6685dc6f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

5,114
nvidia-gpu-exporterkubeblocksVerified publisher0.3.11 of 1See more

nvidia-gpu-exporter kubeblocks 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,500
openebskubeblocksVerified publisher3.10.02 of 3See more

openebs kubeblocks 3.10.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
openebs/node-disk-operator:2.1.06afe2123c457
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

10,568
spiderpoolkubeblocksVerified publisher1.2.02 of 4See more

spiderpool kubeblocks 1.2.0

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
perl@5.30.0-9ubuntu0.5
no fix listed
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

8,457
juicefs-tenantkubegems1.0.11 of 3See more

juicefs-tenant kubegems 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kubegems/redis:7.2.5-debian-12-r2870ee3a77add
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,120
kube-janitorkube-janitor0.3.31 of 1See more

kube-janitor kube-janitor 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hjacobs/kube-janitor:23.7.0fbb303ed463c
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

3,700
apm-serverkube-opsVerified publisher0.1.21 of 1See more

apm-server kube-ops 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
elastic/apm-server:7.17.6c7a1c63257d0
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,196
kube-ovnkube-ovn-test1.14.01 of 1See more

kube-ovn kube-ovn-test 1.14.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kubeovn/kube-ovn:v1.14.06722b54eb5c0
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

4,991
kube-httpcachekubernetes-replicator0.9.11 of 1See more

kube-httpcache kubernetes-replicator 0.9.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-httpcache:stable2169032c5840
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

4,118
kube-mailkubernetes-replicator0.11.11 of 3See more

kube-mail kubernetes-replicator 0.11.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-mail:latest04f1099241fc
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

2,444
databend-metakubesphere-stable0.7.31 of 1See more

databend-meta kubesphere-stable 0.7.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,448
databend-querykubesphere-stable0.8.31 of 1See more

databend-query kubesphere-stable 0.8.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
datafuselabs/databend-query:v1.2.279a936843b85b4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,448
deepflowkubesphere-stable6.2.6062 of 8See more

deepflow kubesphere-stable 6.2.606

2 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
perl@5.30.0-9ubuntu0.2
no fix listed
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

18,394
iomeshkubesphere-stable1.1.04 of 25See more

iomesh kubesphere-stable 1.1.0

4 of the 25 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.7.25d3f9bf9240b
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
iomesh/node-disk-exporter:1.8.0f03148764f38
perl@5.30.0-9ubuntu0.2
no fix listed
iomesh/node-disk-manager:1.8.0002c4b92fd34
perl@5.30.0-9ubuntu0.2
no fix listed
iomesh/node-disk-operator:1.8.0f6c76380db34
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

48,833
IOMeshkubesphere-stable1.2.04 of 25See more

IOMesh kubesphere-stable 1.2.0

4 of the 25 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.8.01a151f602451
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
iomesh/node-disk-exporter:1.8.0f03148764f38
perl@5.30.0-9ubuntu0.2
no fix listed
iomesh/node-disk-manager:1.8.0-2292ad270082e
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

46,507
pulsarkubesphere-stable2.7.131 of 3See more

pulsar kubesphere-stable 2.7.13

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

14,368
clickhousekubesphere-testVerified publisher0.1.11 of 2See more

clickhouse kubesphere-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
radondb/clickhouse-server:v21.1.3.32-stable4732df471073
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

6,701
csi-neonsankubesphere-testVerified publisher1.3.01 of 6See more

csi-neonsan kubesphere-test 1.3.0

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
csiplugin/csi-neonsan:v1.2.21fa83d45417f
perl@5.22.1-9ubuntu0.9
no fix listed

Open the chart page →

18,482
mongodbkubesphere-testVerified publisher0.3.21 of 2See more

mongodb kubesphere-test 0.3.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:4.2.16ca49afbcb2b
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

9,628
mysqlkubesphere-testVerified publisher1.0.21 of 3See more

mysql kubesphere-test 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,381
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

9,384
xenondbkubesphere-testVerified publisher1.0.01 of 3See more

xenondb kubesphere-test 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
xenondb/percona:5.7.330e26872a2b67
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,381
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
penpotapp/exporter:2.2.15c835ffd87ab
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

17,002
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.42 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

2 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

20,299
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,460
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

6,879
sample-operatorkusionstackVerified publisher0.1.21 of 1See more

sample-operator kusionstack 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
chaerr/kridge:demo-operator-v0.1.266833deec017
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

2,501
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

3,143
keycloak-application-platform-configkvalitetsitVerified publisher0.0.291 of 1See more

keycloak-application-platform-config kvalitetsit 0.0.29

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

3,373
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

16,537
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

7,842
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

26,371
pageslatif-pages1.0.02 of 3See more

pages latif-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
pageslavanya-pages1.0.02 of 3See more

pages lavanya-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

4,270
owntracks-exporterleprechaun-charts0.1.111 of 1See more

owntracks-exporter leprechaun-charts 0.1.11

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

3,448
jackettlib42Verified publisher1.1.01 of 1See more

jackett lib42 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
lib42/jackett:latesta55596cda383
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,632
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,456
lightlyticslightlytics0.1.212 of 2See more

lightlytics lightlytics 0.1.21

2 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,130
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

37,518
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

10,773
pagesliviu884422-pages1.0.02 of 3See more

pages liviu884422-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
locustio/locust:2.24.151d866285170
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,516
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

6,674
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,970

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
perl@5.26.1-6ubuntu0.7
no fix listed
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
perl@5.26.1-6ubuntu0.6
no fix listed
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
perl@5.36.0-7
5.36.0-7+deb12u3
1
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
perl@5.26.1-6ubuntu0.5
no fix listed
1
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
1
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
perl@5.26.1-6ubuntu0.5
no fix listed
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.