StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,790 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,790 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

10,859
giteawenerme12.7.03 of 4See more

gitea wenerme 12.7.0

3 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

8,874
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

9,183
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

15,288
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
openebs/node-disk-operator:2.1.06afe2123c457
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

10,587
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.7.45f2a56b95266
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

15,044
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

9,320
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

7,664
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

6,326
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,559
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

14,173
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

11,603
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,697
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
hamzaarshad10/querypodpy:1.7154f38e8668e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
murtazashah46/helmfile:latest4d11726cf803
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

13,783
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

2,142
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,684
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
perl@5.26.1-6ubuntu0.5
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

9,256

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
perl@5.36.0-7
5.36.0-7+deb12u3
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-accountingservice6d051840bb29
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-frontendproxy9fdec1be03e4
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/open-telemetry/demo:1.12.0-emailservicea1f5cebb5240
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
ghcr.io/open-telemetry/demo:1.12.0-recommendationserviceb294a4278407
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
perl@5.36.0-7
5.36.0-7+deb12u3
1
ghcr.io/paradigmxyz/reth:v1.3.121e5290e8b743
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
perl@5.26.1-6ubuntu0.5
no fix listed
1
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
perl@5.36.0-7
5.36.0-7+deb12u3
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
perl@5.30.0-9ubuntu0.3
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
perl@5.30.0-9ubuntu0.3
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
perl@5.30.0-9ubuntu0.3
no fix listed
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
perl@5.30.0-9ubuntu0.2
no fix listed
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
perl@5.30.0-9ubuntu0.5
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
perl@5.30.0-9ubuntu0.5
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.