StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

6,220
mollysocketmollysocketVerified publisher0.2.81 of 1See more

mollysocket mollysocket 0.2.8

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

3,028
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:5.041108d183e97
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

5,217
camera-viewermoreillonVerified publisher0.2.12 of 4See more

camera-viewer moreillon 0.2.1

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
moreillon/camera-viewer:lateste418cc694bd5
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

11,694
group-managermoreillonVerified publisher0.4.42 of 3See more

group-manager moreillon 0.4.4

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
moreillon/group-manager-front:v3.3.1c9f85db3baa5
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

9,886
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5

Open the chart page →

10,998
user-manager-mongodbmoreillonVerified publisher0.6.23 of 4See more

user-manager-mongodb moreillon 0.6.2

3 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
moreillon/user-manager-front:v5.0.3b067dbbbb6af
perl@5.36.0-7
5.36.0-7+deb12u3
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

23,263
user-manager-neo4jmoreillonVerified publisher0.9.74 of 6See more

user-manager-neo4j moreillon 0.9.7

4 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
moreillon/group-manager-front:v3.3.1c9f85db3baa5
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
moreillon/user-manager:v5.0.2e1c9bfab5c16
perl@5.36.0-7
5.36.0-7+deb12u3
moreillon/user-manager-front:v5.1.06597e6b98d21
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

30,195
genericmorremeyer8.0.01 of 1See more

generic morremeyer 8.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/nginx:1.25.167f9a4f10d14
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

5,602
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

25,989
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

15,731
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

6,646
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

13,711
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

8,946
pagesmuthu-pages1.0.02 of 3See more

pages muthu-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

12,861
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

12,861
clickhousemyaVerified publisher0.2403.11 of 1See more

clickhouse mya 0.2403.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.2ed9640bfff07
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,597
cognativemyaVerified publisher0.2403.31 of 3See more

cognative mya 0.2403.3

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.2ed9640bfff07
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

7,348
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
perl@0:1.28-420.el8
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
0:1.28-423.el8_10
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb

Open the chart page →

9,149
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

9,341
my-helm-chartmy-helm-charts-2024Verified publisher0.1.01 of 1See more

my-helm-chart my-helm-charts-2024 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
shamimkuet/nginx:1.0.2b82902a76a04
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,383
Practica_4_helmmy-heml-appVerified publisher0.1.03 of 7See more

Practica_4_helm my-heml-app 0.1.0

3 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
perl@5.26.1-6ubuntu0.6
no fix listed
library/mongo:5.0.6-focal8e70544b6c76
perl@5.30.0-9ubuntu0.2
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

27,812
mystoremystore-chart0.1.02 of 3See more

mystore mystore-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hazegoodlife/haaze:veggiesite50f02d2d5d4d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
hazegoodlife/haaze:milksite8d4c63169e14
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

8,776
myweatherhelmmyweather1.3.112 of 7See more

myweatherhelm myweather 1.3.11

2 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hecrom/myweatherangularclient:1.3.11bb0372939c19
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

17,411
smallandnaj980.0.51 of 1See more

smalland naj98 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

3,024
pagesnarain1.0.02 of 3See more

pages narain 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
pagesnarasimha-pages1.0.02 of 3See more

pages narasimha-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

12,839
pagesnavin-brixton1.0.02 of 3See more

pages navin-brixton 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
incorencsaVerified publisher1.38.02 of 29See more

incore ncsa 1.38.0

2 of the 29 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
bitnamilegacy/postgresql:16.4.03ba6e6f11388
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

15,408
smilencsaVerified publisher1.1.07 of 23See more

smile ncsa 1.1.0

7 of the 23 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
perl@5.30.0-9ubuntu0.4
no fix listed
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
perl@5.26.1-6ubuntu0.6
no fix listed
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
perl@5.36.0-7
5.36.0-7+deb12u3
socialmediamacroscope/image_crawler:0.1.2f508216be63c
perl@5.26.1-6ubuntu0.6
no fix listed
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
perl@5.36.0-7
5.36.0-7+deb12u3
socialmediamacroscope/preprocessing:0.1.3ca863306314b
perl@5.36.0-7
5.36.0-7+deb12u3
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

109,485
neosyncneosyncVerified publisher0.5.412 of 3See more

neosync neosync 0.5.41

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

7,056
apineosync-apiVerified publisher0.5.411 of 1See more

api neosync-api 0.5.41

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

2,755
workerneosync-workerVerified publisher0.5.411 of 1See more

worker neosync-worker 0.5.41

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

2,732
netbirdnetbird1.9.01 of 4See more

netbird netbird 1.9.0

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

6,367
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

7,413
nfl-walletnfl-walletVerified publisher0.1.31 of 4See more

nfl-wallet nfl-wallet 0.1.3

1 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
perl@0:1.28-423.el8_10
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-3.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.30-474.module+el8.10.0+24099+8aa2f756
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

13,047
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,731
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,731
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,510
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

9,831
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

22,713
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

13,331
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

13,405
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

13,387
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
perl@5.18.2-2ubuntu1
no fix listed

Open the chart page →

41,455
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
perl@5.26.1-6ubuntu0.5
no fix listed
linuxserver/codimd:latestb801bbcf6386
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

27,486
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

27,667
firecrawlobeoneVerified publisher3.0.31 of 5See more

firecrawl obeone 3.0.3

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

9,895

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ddosify/selfhosted_backend:3.2.93c11e3182652
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
deconzcommunity/deconz:2.29.2062de2362641
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
perl@5.30.0-9ubuntu0.2
no fix listed
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
defactops/defactops-backend:1.0.2307b663c0092a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
dellcloud/category:distributed02fc234353a9
perl@5.30.0-9ubuntu0.2
no fix listed
1
dellcloud/pages:1.04d2eb25b9225
perl@5.30.0-9ubuntu0.2
no fix listed
1
devopsgoofy/k8s-platform:latestad865312099f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
perl@5.30.0-9ubuntu0.2
no fix listed
1
djjudas21/alertify:0.1.0ba22be670c37
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
dniel/api-posts:master45a667852f2a
perl@5.26.1-6ubuntu0.3
no fix listed
1
dobtc/bitcoin:25.1a870f7cb1105
perl@5.36.0-7
5.36.0-7+deb12u3
1
domainmod/domainmod:4.23.04017bfe4c597
perl@5.36.0-7
5.36.0-7+deb12u3
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
perl@5.30.0-9ubuntu0.5
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
dremio/dremio-oss:24.1.080ed2e3b7c43
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
drorivry4/rego:lateste035d49b15ca
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
drpcorg/dshackle:0.54.08858fae1859d
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
dserio83/velero-api:0.3.16b3d9115fee2
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
dserio83/velero-watchdog:0.1.8d5deae589229
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
duck1123/cert-downloader:latest0e29f19fa67c
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
duck1123/lnd-fileserver:latest9d6fb247b714
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
elastic/apm-server:7.17.6c7a1c63257d0
perl@5.30.0-9ubuntu0.2
no fix listed
1
elastictranscoder/media:627e21dc963ab3858c6b
perl@5.26.1-6ubuntu0.3
no fix listed
1
elastictranscoder/media-storage:f6d861a026208b8c2359
perl@5.26.1-6ubuntu0.3
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
perl@5.26.1-6ubuntu0.3
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
perl@5.26.1-6ubuntu0.3
no fix listed
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
perl@5.30.0-9ubuntu0.2
no fix listed
1
emqx/ecp-ui:2.5.1e33e9816f147
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
enclavenetworks/enclave:latest0a99759300d1
perl@5.30.0-9ubuntu0.5
no fix listed
1
engrmth/bnkr:2.1.06d8464e6f0e8
perl@5.30.0-9ubuntu0.2
no fix listed
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
perl@5.26.1-6ubuntu0.5
no fix listed
1
envoyproxy/envoy:v1.30.92956bd9de830
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.33.056da5afd7df3
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.31-latestcaa5b411be16
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.30.1e596fda6a0ce
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.18.2e8b37c1d7578
perl@5.26.1-6ubuntu0.5
no fix listed
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
perl@5.26.1-6ubuntu0.6
no fix listed
1
erigontech/erigon:v2.61.288706754b627
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
esphome/esphome:2024.3.09ab8cc88b28c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
esphome/esphome:2024.12.2b2c6322700ac
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
esphome/esphome:2025.3.0def8b6e4f517
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
perl@5.30.0-9ubuntu0.2
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
perl@5.22.1-9ubuntu0.2
no fix listed
1
ethersphere/bee:2.2.0a884fd84b72f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.