StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,262
of 17,781 indexed, latest versions
Container images
1,319
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,262 of 17,781 indexed charts deploy, on 1,319 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,293
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,262 by stars
ChartLatestAffected imagesRadar Score
fahclientpcktdmp2.6.01 of 2See more

fahclient pcktdmp 2.6.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
foldingathome/fah-gpu:latest5ef7742d1eb4
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

4,727
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

7,576
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
perl@5.30.0-9ubuntu0.2
no fix listed
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

31,844
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

5,440
pzserverpzserver0.1.171 of 2See more

pzserver pzserver 0.1.17

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
lis314/project-zomboid-docker:latestaa2089c37920
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,201
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

6,796
rabbitmqrabbitmq-magefleet1.2.01 of 1See more

rabbitmq rabbitmq-magefleet 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

2,762
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest1336a777f9a4
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

7,405
redis-sentinel-gatewayredis-sentinel-gatewayVerified publisher1.0.21 of 1See more

redis-sentinel-gateway redis-sentinel-gateway 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
promzeus/redis-sentinel-gateway:v182f6d56e280b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,652
reportportalreportportal-ioOfficialVerified publisher26.8.121 of 15See more

reportportal reportportal-io 26.8.12

1 of the 15 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

11,869
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

7,432
atuinrm3lVerified publisher0.11.01 of 3See more

atuin rm3l 0.11.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r890fda44bfa42
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

6,521
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

9,837
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

10,120
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

6,045
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

6,879
kube-state-metricsromanow-helm-chartsVerified publisher1.7.21 of 1See more

kube-state-metrics romanow-helm-charts 1.7.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/kube-state-metrics:204a3044b384b
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

2,654
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

7,529
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

12,930
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

5,315
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

13,541
kyoorubxkubeVerified publisher0.1.104 of 9See more

kyoo rubxkube 0.1.10

4 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

30,234
conference-appsalaboy1.0.03 of 7See more

conference-app salaboy 1.0.0

3 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3digest-pinnedce9ce8293e4e
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9digest-pinnedbb64bf14467d
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525digest-pinned799c35f9f306
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

10,905
schemaheroschemahero1.4.01 of 1See more

schemahero schemahero 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
schemahero/schemahero-manager:0.22.11609e1a05cd3
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

2,139
sentry-k8ssentry-k8sVerified publisher1.4.12 of 11See more

sentry-k8s sentry-k8s 1.4.1

2 of the 11 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

16,449
seq-input-gelfseq-input-gelfVerified publisher0.3.11 of 2See more

seq-input-gelf seq-input-gelf 0.3.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
datalust/seq-input-gelf:3.0.441-x643de34aed5642
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

3,514
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
dserio83/velero-watchdog:0.1.8d5deae589229
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

11,532
mssqlserver-2019simcube1.2.31 of 1See more

mssqlserver-2019 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

6,817
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

4,238
gitlab-omnibusslamdev0.1.61 of 2See more

gitlab-omnibus slamdev 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
daedalusproject/base_kubectl:latest6f72b5119eda
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

2,810
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,928
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
perl@5.30.0-9ubuntu0.3
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
perl@5.30.0-9ubuntu0.3
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

45,832
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,676
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

10,380
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,661
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

13,486
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

24,930
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
kong/kong:3.9.16addf50e6bd8
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

18,075
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

2,100
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

9,102
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

9,102
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

4,020
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

3,764
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

3,764
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

12,581
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,249
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

5,225
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
perl@5.30.0-9ubuntu0.4
no fix listed
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

26,657
phpipamvquieVerified publisher1.0.31 of 3See more

phpipam vquie 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mariadb:10.11.21c33370a599c
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

7,025
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

15,970

Container images carrying it

1,319 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
camunda/zeebe:8.4.5ab5abc09e407
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
castlemock/castlemock:latestb7f3f1527ba9
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.2
1
castopod/castopod:1.12.101fd37280cbb2
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
perl@5.26.1-lp151.8.37
5.40.2-3.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
perl@5.26.1-lp151.8.37
5.40.2-3.1
1
chaerr/kridge:demo-operator-v0.1.266833deec017
perl@5.30.0-9ubuntu0.4
no fix listed
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
perl@5.18.2-2ubuntu1.7
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
perl@5.30.0-9ubuntu0.2
no fix listed
1
cheveo/azp-agent:1.0.282240f890884
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
cheyang/distributed-tf:1.6.046cc34755493
perl@5.22.1-9ubuntu0.2
no fix listed
1
chriseaton/adventureworks:latest54c3384ce701
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
circleci/runner:launch-agent9bdc62f02162
perl@5.30.0-9ubuntu0.5
no fix listed
1
ciscolabs/msm-nc:0710202336d02faad958
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
citizenstig/httpbin:latestb81c818ccb86
perl@5.22.1-9
no fix listed
1
ckulka/baikal:0.10.1-nginx434bdd162247
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
clickhouse/clickhouse-server:24.81ffa82edee00
perl@5.30.0-9ubuntu0.5
no fix listed
1
clickhouse/clickhouse-server:24.4.12e6587b81a26
perl@5.30.0-9ubuntu0.5
no fix listed
1
clickhouse/clickhouse-server:23.8512bb8a21483
perl@5.30.0-9ubuntu0.5
no fix listed
1
clickhouse/clickhouse-server:25.3.2.398745843b17f9
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
cloudve/janis-terminal:latestaf56e77ca587
perl@5.26.1-6ubuntu0.3
no fix listed
1
cloudve/ttyd:latestd79c1c5881c0
perl@5.26.1-6ubuntu0.3
no fix listed
1
coderenvs/timescale:1.44.676fd37fe6830
perl@0:1.28-422.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-2.el8_9.1
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.28-423.el8_10
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb
1
consensys/teku:25.4.1bf6ecd2ea716
perl@5.38.2-3.2build2.1
5.38.2-3.2ubuntu0.2
1
contentsquareplatform/chproxy:v1.26.524555f22d4be
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
cortezaproject/corteza:2024.9.08eb7a26605c9
perl@5.30.0-9ubuntu0.5
no fix listed
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
countly/countly-server:25.05.4e3c238248f99
perl@5.30.0-9ubuntu0.5
no fix listed
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
perl@5.26.1-6ubuntu0.2
no fix listed
1
cribl/cribl:3.0.2762747cb6796
perl@5.26.1-6ubuntu0.5
no fix listed
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
perl@5.22.1-9ubuntu0.9
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
perl@5.36.0-7
5.36.0-7+deb12u3
1
daedalusproject/base_kubectl:latest6f72b5119eda
perl@5.30.0-9ubuntu0.2
no fix listed
1
dannielkil/book-frontend:latest937993927694
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
darthsim/imgproxy:v3.26476cb08c816a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2
1
daskdev/dask-notebook:1.1.0052630f5ca04
perl@5.26.1-6ubuntu0.3
no fix listed
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
perl@5.26.1-6ubuntu0.6
no fix listed
1
datadog/agent:6aad9994de6a7
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
1
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
datafuselabs/databend-query:v1.2.279a936843b85b4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
datalayers/datalayers:v2.2.1017b292079239
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
datalust/seq:5.0.832-pre9c731bb207a6
perl@5.22.1-9ubuntu0.2
no fix listed
1
datalust/seq-input-gelf:3.0.441-x643de34aed5642
perl@5.30.0-9ubuntu0.3
no fix listed
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
ddosify/alaz:v0.12.0ea602056d9ce
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.