StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
giteagiteaOfficialVerified publisher12.7.03 of 4See more

gitea gitea 12.7.0

3 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

8,842
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

6,597
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

11,372
openebsopenebsOfficialVerified publisher4.6.12 of 35See more

openebs openebs 4.6.1

2 of the 35 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.2
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

24,009
apisixapisix2.17.01 of 3See more

apisix apisix 2.17.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

3,096
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
perl@5.26.1-6ubuntu0.6
no fix listed

Open the chart page →

5,557
openldap-stack-hahelm-openldapVerified publisher4.3.31 of 5See more

openldap-stack-ha helm-openldap 4.3.3

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jpgouin/openldap:2.6.9-fixbfdd0088c776
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,948
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

9,194
grafana-agentgrafana0.44.21 of 2See more

grafana-agent grafana 0.44.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
grafana/agent:v0.44.23364714a2f64
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

3,514
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
perl@5.30.0-9ubuntu0.2
no fix listed
milvusdb/milvus:v2.2.13a3a55e1c1497
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

32,353
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

10,648
signozsignoz0.141.11 of 5See more

signoz signoz 0.141.1

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.972aa1e4c1ec5
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,582
weblateweblateOfficialVerified publisher0.5.362 of 3See more

weblate weblate 0.5.36

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/redis:latest5927ff3702df
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

6,761
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,660
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

4,808
difydoubanVerified publisher0.10.02 of 6See more

dify douban 0.10.0

2 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

19,497
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

3,645
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

6,949
stacks-blockchainhirosystemsVerified publisher2.2.21 of 1See more

stacks-blockchain hirosystems 2.2.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

1,385
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
perl@5.22.1-9ubuntu0.6
no fix listed
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

23,992
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

4,159
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.02 of 5See more

openproject openproject-helm-charts 13.11.0

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
openproject/hocuspocus:release-338001b288dc1359dfb5
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

19,998
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

11,402
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

33,907
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

3,700
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

6,550
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

8,387
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

6,012
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
perl@5.30.0-9ubuntu0.5
no fix listed
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

12,830
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

8,473
litellm-helmlitellm1.101.01 of 2See more

litellm-helm litellm 1.101.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,574
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

3,422
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

15,607
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,917
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

11,971
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,364
milvusmilvus-helm5.0.281 of 4See more

milvus milvus-helm 5.0.28

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

10,764
prefect-serverprefectVerified publisher2026.9.141419101 of 2See more

prefect-server prefect 2026.9.14141910

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,448
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

18,570
codefreshcodefresh-onpremOfficialVerified publisher2.12.134 of 42See more

codefresh codefresh-onprem 2.12.13

4 of the 42 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
bitnamilegacy/rabbitmq:4.1.39e635efba431
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

14,615
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2api:3.86f56d239d280
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2auth:3.833ecfda16608
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2notifier:3.8f190a6212195
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2rulesengine:3.8259503496ff9
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2scheduler:3.8b1de2055c362
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2sensorcontainer:3.8b1a338f64773
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2stream:3.81c8904a3bf67
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2timersengine:3.81bf35bfaf00c
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2web:3.809989a26c8b7
perl@5.30.0-9ubuntu0.5
no fix listed
stackstorm/st2workflowengine:3.819fdfffdbba8
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

96,984
supabasetokens-studioVerified publisher1.0.05 of 14See more

supabase tokens-studio 1.0.0

5 of the 14 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
supabase/edge-runtime:v1.59.0eff9c554d649
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
supabase/postgres-meta:v0.84.2d0a96973e9f1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
supabase/realtime:v2.33.8d207e6e23ad3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
supabase/studio:20241021-9f9b08326d8070c55e9
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

23,263
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

8,530
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

3,493
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

7,896
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,492
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,453
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

4,281
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
5.36.0-7+deb12u3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

31,447
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

3,645

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
perl@5.36.0-7
5.36.0-7+deb12u3
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-accountingservice6d051840bb29
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-frontendproxy9fdec1be03e4
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/open-telemetry/demo:1.12.0-emailservicea1f5cebb5240
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/open-telemetry/demo:1.12.0-recommendationserviceb294a4278407
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
perl@5.36.0-7
5.36.0-7+deb12u3
1
ghcr.io/paradigmxyz/reth:v1.3.121e5290e8b743
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
perl@5.26.1-6ubuntu0.5
no fix listed
1
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
perl@5.36.0-7
5.36.0-7+deb12u3
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
perl@5.30.0-9ubuntu0.3
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
perl@5.30.0-9ubuntu0.3
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
perl@5.30.0-9ubuntu0.3
no fix listed
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
perl@5.30.0-9ubuntu0.5
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.