StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,267
of 17,787 indexed, latest versions
Container images
1,323
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,267 of 17,787 indexed charts deploy, on 1,323 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,297
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,267 by stars
ChartLatestAffected imagesRadar Score
kresusrm3lVerified publisher0.2.12 of 3See more

kresus rm3l 0.2.1

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bnjbvr/kresus:0.22.137e216b182c8
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

15,623
pagesroccohiggins-pages1.0.02 of 3See more

pages roccohiggins-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

9,275
rocketchat-voiprocketchat-server0.1.01 of 1See more

rocketchat-voip rocketchat-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
rocketchat/freeswitch:stablecfba5c20a5cc
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

5,329
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

9,152
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

12,999
calertromholdings0.0.11 of 1See more

calert romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

4,688
devtron-enterpriseromholdings48.0.06 of 28See more

devtron-enterprise romholdings 48.0.0

6 of the 28 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
5.36.0-7+deb12u3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
perl@5.22.1-9ubuntu0.9
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

66,542
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

4,969
devtron-operatorromholdings0.23.35 of 11See more

devtron-operator romholdings 0.23.3

5 of the 11 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
perl@5.36.0-7
5.36.0-7+deb12u3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
quay.io/devtron/postgres:14.91b594392f7cb
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

31,447
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

11,957
migration-incluster-cdromholdings0.10.01 of 1See more

migration-incluster-cd romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,699
pagesronan-pages1.0.02 of 3See more

pages ronan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,318
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

6,940
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,406
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,612
prepull-daemonsetrstudioVerified publisher0.0.51 of 2See more

prepull-daemonset rstudio 0.0.5

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/ubuntu:bionic152dc042452c
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

1,720
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,429
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

4,966
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

8,720
orbitalryuunosukeds30.2.01 of 1See more

orbital ryuunosukeds3 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ryuunosukeds3/orbital:latest0879f7261b10
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

2,556
test-helm-app1saam-helm-test0.1.01 of 1See more

test-helm-app1 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hamidyousefi93/saam-test:latestc34f071f6ed0
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

3,374
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

17,736
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

14,792
sagawisesagawiseVerified publisher0.1.01 of 3See more

sagawise sagawise 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
venturenox/redis:latest83b471c193ba
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,104
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

16,159
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
perl@5.34.0-3ubuntu1
5.34.0-3ubuntu1.5

Open the chart page →

8,073
pagessamanvithkaranth1.0.02 of 3See more

pages samanvithkaranth 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
evsantisbon0.2.02 of 5See more

ev santisbon 0.2.0

2 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
santisbon/evwatcher:latestc4e994ca4540
perl@5.36.0-7
5.36.0-7+deb12u3
santisbon/evworker:lateste807283f8d69
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

12,090
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
santisbon/speedtest:latest8ee3a1697227
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

11,314
pagessarubits-pages1.0.02 of 3See more

pages sarubits-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

9,340
jellyfinsb-helm-charts0.4.01 of 1See more

jellyfin sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.317c3a8d9dddb
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,864
mongodbsb-helm-charts0.4.01 of 1See more

mongodb sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:7.0.140032d2ca20db
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

4,095
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,065
vaultwardensb-helm-charts0.4.01 of 1See more

vaultwarden sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
vaultwarden/server:1.34.384fd8a47f58d
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

3,210
wordpresssb-helm-charts0.4.01 of 2See more

wordpress sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/wordpress:6.4.3-apache8ae66efb09a2
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

12,009
mindustryschichtelVerified publisher0.1.11 of 1See more

mindustry schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
pschichtel/mindustry-server:v145.1b543e9c2d371
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

3,265
satisfactoryschichtelVerified publisher0.3.31 of 1See more

satisfactory schichtel 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.9464d11e36e10
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5

Open the chart page →

3,564
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
typesense/typesense:0.25.1035ccfbc3fd8
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

4,109
unboundschoolguys-helmcharts0.1.11 of 1See more

unbound schoolguys-helmcharts 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
mvance/unbound:1.20.04bf67b567f39
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,748
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,570
pagessekharpkube1.0.02 of 3See more

pages sekharpkube 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

23,022
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
perl@0:1.28-419.el8_4.1
perl-Carp@1.42-396.el8
perl-constant@1.33-396.el8
perl-Data-Dumper@2.167-399.el8
perl-Digest@1.17-395.el8
perl-Digest-MD5@2.55-396.el8
perl-Encode@4:2.97-3.el8
perl-Exporter@5.72-396.el8
perl-File-Path@2.15-2.el8
perl-File-Temp@0.230.600-1.el8
perl-Getopt-Long@1:2.50-4.el8
perl-HTTP-Tiny@0.074-1.el8
perl-IO-Socket-IP@0.39-5.el8
perl-libnet@3.11-3.el8
perl-MIME-Base64@3.15-396.el8
perl-parent@1:0.237-1.el8
perl-PathTools@3.74-1.el8
perl-Pod-Escapes@1:1.07-395.el8
perl-Pod-Perldoc@3.28-396.el8
perl-Pod-Simple@1:3.35-395.el8
perl-Pod-Usage@4:1.69-395.el8
perl-podlators@4.11-1.el8
perl-Scalar-List-Utils@3:1.49-2.el8
perl-Socket@4:2.027-3.el8
perl-Storable@1:3.11-3.el8
perl-Term-ANSIColor@4.06-396.el8
perl-Term-Cap@1.17-395.el8
perl-Text-ParseWords@3.30-395.el8
perl-Text-Tabs+Wrap@2013.0523-395.el8
perl-Thread-Queue@3.13-1.el8
perl-threads@1:2.21-2.el8
perl-threads-shared@1.58-2.el8
perl-Time-Local@1:1.280-1.el8
perl-Unicode-Normalize@1.25-396.el8
perl-URI@1.73-3.el8
0:1.28-423.el8_10
0:1.50-439.module+el8.10.0+21354+3ad137bb
0:1.33-1001.module+el8.10.0+21354+3ad137bb
0:2.174-440.module+el8.10.0+21354+3ad137bb
0:1.20-1.module+el8.10.0+21354+3ad137bb
0:2.58-1.module+el8.10.0+21354+3ad137bb
4:3.08-461.module+el8.10.0+21354+3ad137bb
0:5.74-458.module+el8.10.0+21354+3ad137bb
0:2.16-439.module+el8.10.0+21354+3ad137bb
1:0.231.100-1.module+el8.10.0+21354+3ad137bb
1:2.52-1.module+el8.10.0+21354+3ad137bb
0:0.078-1.module+el8.10.0+21354+3ad137bb
0:0.41-2.module+el8.10.0+21354+3ad137bb
0:3.13-1.module+el8.10.0+21354+3ad137bb
0:3.15-1001.module+el8.10.0+21354+3ad137bb
1:0.238-457.module+el8.10.0+21354+3ad137bb
0:3.78-439.module+el8.10.0+21354+3ad137bb
1:1.07-396.module+el8.10.0+21354+3ad137bb
0:3.28.01-443.module+el8.10.0+21354+3ad137bb
1:3.42-1.module+el8.10.0+21354+3ad137bb
4:2.01-1.module+el8.10.0+21354+3ad137bb
1:4.14-457.module+el8.10.0+21354+3ad137bb
4:1.55-457.module+el8.10.0+21354+3ad137bb
4:2.031-1.module+el8.10.0+21354+3ad137bb
1:3.21-457.module+el8.10.0+21354+3ad137bb
0:5.01-458.module+el8.10.0+21354+3ad137bb
0:1.17-396.module+el8.10.0+21354+3ad137bb
0:3.30-396.module+el8.10.0+21354+3ad137bb
0:2013.0523-396.module+el8.10.0+21354+3ad137bb
0:3.14-457.module+el8.10.0+21354+3ad137bb
1:2.25-457.module+el8.10.0+21354+3ad137bb
0:1.61-457.module+el8.10.0+21354+3ad137bb
2:1.300-4.module+el8.10.0+21354+3ad137bb
0:1.27-458.module+el8.10.0+21354+3ad137bb
0:1.76-5.module+el8.10.0+21354+3ad137bb

Open the chart page →

21,997
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.16d210dc69321e
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

10,972
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

5,496
first-chartshashkist-test0.1.01 of 3See more

first-chart shashkist-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,934
pagesshrutiujlan-pages1.0.02 of 3See more

pages shrutiujlan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,233

Container images carrying it

1,323 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ddosify/selfhosted_backend:3.2.93c11e3182652
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
deconzcommunity/deconz:2.29.2062de2362641
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
perl@5.30.0-9ubuntu0.2
no fix listed
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
defactops/defactops-backend:1.0.2307b663c0092a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
dellcloud/category:distributed02fc234353a9
perl@5.30.0-9ubuntu0.2
no fix listed
1
dellcloud/pages:1.04d2eb25b9225
perl@5.30.0-9ubuntu0.2
no fix listed
1
devopsgoofy/k8s-platform:latestad865312099f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
perl@5.30.0-9ubuntu0.2
no fix listed
1
djjudas21/alertify:0.1.0ba22be670c37
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
dniel/api-posts:master45a667852f2a
perl@5.26.1-6ubuntu0.3
no fix listed
1
dobtc/bitcoin:25.1a870f7cb1105
perl@5.36.0-7
5.36.0-7+deb12u3
1
domainmod/domainmod:4.23.04017bfe4c597
perl@5.36.0-7
5.36.0-7+deb12u3
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
perl@5.30.0-9ubuntu0.5
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
dremio/dremio-oss:24.1.080ed2e3b7c43
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
drorivry4/rego:lateste035d49b15ca
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
drpcorg/dshackle:0.54.08858fae1859d
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
dserio83/velero-api:0.3.16b3d9115fee2
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
dserio83/velero-watchdog:0.1.8d5deae589229
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
duck1123/cert-downloader:latest0e29f19fa67c
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
duck1123/lnd-fileserver:latest9d6fb247b714
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
elastic/apm-server:7.17.6c7a1c63257d0
perl@5.30.0-9ubuntu0.2
no fix listed
1
elastictranscoder/media:627e21dc963ab3858c6b
perl@5.26.1-6ubuntu0.3
no fix listed
1
elastictranscoder/media-storage:f6d861a026208b8c2359
perl@5.26.1-6ubuntu0.3
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
perl@5.26.1-6ubuntu0.3
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
perl@5.26.1-6ubuntu0.3
no fix listed
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
perl@5.30.0-9ubuntu0.2
no fix listed
1
emqx/ecp-ui:2.5.1e33e9816f147
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
enclavenetworks/enclave:latest0a99759300d1
perl@5.30.0-9ubuntu0.5
no fix listed
1
engrmth/bnkr:2.1.06d8464e6f0e8
perl@5.30.0-9ubuntu0.2
no fix listed
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
perl@5.26.1-6ubuntu0.5
no fix listed
1
envoyproxy/envoy:v1.30.92956bd9de830
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.33.056da5afd7df3
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.31-latestcaa5b411be16
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.30.1e596fda6a0ce
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.18.2e8b37c1d7578
perl@5.26.1-6ubuntu0.5
no fix listed
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
perl@5.26.1-6ubuntu0.6
no fix listed
1
erigontech/erigon:v2.61.288706754b627
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
esphome/esphome:2024.3.09ab8cc88b28c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
esphome/esphome:2024.12.2b2c6322700ac
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
esphome/esphome:2025.3.0def8b6e4f517
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
perl@5.30.0-9ubuntu0.2
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
perl@5.22.1-9ubuntu0.2
no fix listed
1
ethersphere/bee:2.2.0a884fd84b72f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.