StackRadar

CVE-2025-40909

Medium

Advisory

Published 30 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,262
of 17,781 indexed, latest versions
Container images
1,319
deployed by those charts
Fix available
41 of 41
affected packages

Red Hat Security Advisory: perl security update

Carried by container images the latest versions of 1,262 of 17,781 indexed charts deploy, on 1,319 images.

Affected packageAffected versionsFixed inImages
perldeb5.18.2-2ubuntu1, 5.18.2-2ubuntu1.1, 5.18.2-2ubuntu1.4, 5.18.2-2ubuntu1.7+29 more5.34.0-3ubuntu1.5, 5.36.0-7+deb12u3, 5.38.2-3.2ubuntu0.21,293
perlrpm0:1.28-416.el8, 0:1.28-417.el8_3, 0:1.28-419.el8_4.1, 0:1.28-420.el8+8 more0:1.28-423.el8_10, 0:1.30-474.module+el8.10.0+24099+8aa2f756, 0:5.74-474.module+el8.10.0+24099+8aa2f756, 0:5.74-481.1.el9_6+3 more26
perl-Carprpm1.42-396.el80:1.50-439.module+el8.6.0+13324+628a2397, 0:1.50-439.module+el8.10.0+21354+3ad137bb16
perl-constantrpm1.33-396.el80:1.33-1001.module+el8.6.0+13324+628a2397, 0:1.33-1001.module+el8.10.0+21354+3ad137bb16
perl-Exporterrpm5.72-396.el80:5.74-458.module+el8.6.0+13324+628a2397, 0:5.74-458.module+el8.10.0+21354+3ad137bb16
perl-File-Pathrpm2.15-2.el80:2.16-439.module+el8.6.0+13324+628a2397, 0:2.16-439.module+el8.10.0+21354+3ad137bb16
perl-parentrpm1:0.237-1.el81:0.238-457.module+el8.6.0+13324+628a2397, 1:0.238-457.module+el8.10.0+21354+3ad137bb16
perl-PathToolsrpm3.74-1.el80:3.78-439.module+el8.6.0+13324+628a2397, 0:3.78-439.module+el8.10.0+21354+3ad137bb16
perl-Scalar-List-Utilsrpm3:1.49-2.el84:1.55-457.module+el8.6.0+13324+628a2397, 4:1.55-457.module+el8.10.0+21354+3ad137bb16
perl-Socketrpm4:2.027-3.el84:2.031-1.module+el8.6.0+13324+628a2397, 4:2.031-1.module+el8.10.0+21354+3ad137bb16
perl-Text-Tabs+Wraprpm2013.0523-395.el80:2013.0523-396.module+el8.6.0+13324+628a2397, 0:2013.0523-396.module+el8.10.0+21354+3ad137bb16
perl-threadsrpm1:2.21-2.el81:2.25-457.module+el8.6.0+13324+628a2397, 1:2.25-457.module+el8.10.0+21354+3ad137bb16
perl-threads-sharedrpm1.58-2.el80:1.61-457.module+el8.6.0+13324+628a2397, 0:1.61-457.module+el8.10.0+21354+3ad137bb16
perl-Unicode-Normalizerpm1.25-396.el80:1.27-458.module+el8.6.0+13324+628a2397, 0:1.27-458.module+el8.10.0+21354+3ad137bb16
perl-Encoderpm4:2.97-3.el84:3.08-461.module+el8.6.0+13324+628a2397, 4:3.08-461.module+el8.10.0+21354+3ad137bb15
perl-File-Temprpm0.230.600-1.el81:0.231.100-1.module+el8.6.0+13324+628a2397, 1:0.231.100-1.module+el8.10.0+21354+3ad137bb15
perl-Getopt-Longrpm1:2.50-4.el81:2.52-1.module+el8.6.0+13324+628a2397, 1:2.52-1.module+el8.10.0+21354+3ad137bb15
perl-HTTP-Tinyrpm0.074-1.el8, 0.074-1.el8_6.1, 0.074-2.el8, 0.074-2.el8_9.1+1 more0:0.078-1.module+el8.6.0+13324+628a2397, 0:0.078-1.module+el8.10.0+21354+3ad137bb15
perl-MIME-Base64rpm3.15-396.el80:3.15-1001.module+el8.6.0+13324+628a2397, 0:3.15-1001.module+el8.10.0+21354+3ad137bb15
perl-Pod-Escapesrpm1:1.07-395.el81:1.07-396.module+el8.6.0+13324+628a2397, 1:1.07-396.module+el8.10.0+21354+3ad137bb15
perl-podlatorsrpm4.11-1.el81:4.14-457.module+el8.6.0+13324+628a2397, 1:4.14-457.module+el8.10.0+21354+3ad137bb15
perl-Pod-Perldocrpm3.28-396.el80:3.28.01-443.module+el8.6.0+13324+628a2397, 0:3.28.01-443.module+el8.10.0+21354+3ad137bb15
perl-Pod-Simplerpm1:3.35-395.el81:3.42-1.module+el8.6.0+13324+628a2397, 1:3.42-1.module+el8.10.0+21354+3ad137bb15
perl-Pod-Usagerpm4:1.69-395.el84:2.01-1.module+el8.6.0+13324+628a2397, 4:2.01-1.module+el8.10.0+21354+3ad137bb15
perl-Storablerpm1:3.11-3.el81:3.21-457.module+el8.6.0+13324+628a2397, 1:3.21-457.module+el8.10.0+21354+3ad137bb15
perl-Term-ANSIColorrpm4.06-396.el80:5.01-458.module+el8.6.0+13324+628a2397, 0:5.01-458.module+el8.10.0+21354+3ad137bb15
perl-Term-Caprpm1.17-395.el80:1.17-396.module+el8.6.0+13324+628a2397, 0:1.17-396.module+el8.10.0+21354+3ad137bb15
perl-Text-ParseWordsrpm3.30-395.el80:3.30-396.module+el8.6.0+13324+628a2397, 0:3.30-396.module+el8.10.0+21354+3ad137bb15
perl-Time-Localrpm1:1.280-1.el82:1.300-4.module+el8.6.0+13324+628a2397, 2:1.300-4.module+el8.10.0+21354+3ad137bb15
perl-Data-Dumperrpm2.167-399.el80:2.174-440.module+el8.6.0+13324+628a2397, 0:2.174-440.module+el8.10.0+21354+3ad137bb14
perl-Digestrpm1.17-395.el80:1.20-1.module+el8.6.0+13324+628a2397, 0:1.20-1.module+el8.10.0+21354+3ad137bb13
perl-Digest-MD5rpm2.55-396.el80:2.58-1.module+el8.6.0+13324+628a2397, 0:2.58-1.module+el8.10.0+21354+3ad137bb13
perl-IO-Socket-IPrpm0.39-5.el80:0.41-2.module+el8.6.0+13324+628a2397, 0:0.41-2.module+el8.10.0+21354+3ad137bb13
perl-libnetrpm3.11-3.el80:3.13-1.module+el8.6.0+13324+628a2397, 0:3.13-1.module+el8.10.0+21354+3ad137bb13
perl-URIrpm1.73-3.el80:1.76-5.module+el8.6.0+13324+628a2397, 0:1.76-5.module+el8.10.0+21354+3ad137bb13
perl-Thread-Queuerpm3.13-1.el80:3.14-457.module+el8.10.0+21354+3ad137bb2
perl-Compress-Raw-Bzip2rpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
perl-Compress-Raw-Zlibrpm2.081-1.el80:2.096-2.module+el8.10.0+21354+3ad137bb1
perl-Digest-SHArpm1:6.02-1.el81:6.02-2.module+el8.10.0+21354+3ad137bb1
perl-Encode-Localerpm1.05-10.module+el8.3.0+6498+9eecfe510:1.05-10.module+el8.10.0+21354+3ad137bb1
perl-IO-Compressrpm2.081-1.el80:2.096-1.module+el8.10.0+21354+3ad137bb1
OSV records
DEBIAN-CVE-2025-40909RHSA-2025:11545RHSA-2025:11804RHSA-2025:11805RHSA-2026:37070RHSA-2026:8096RLSA-2025:11804UBUNTU-CVE-2025-40909openSUSE-SU-2025:15258-1
Also known as
USN-7678-1

Charts affected

1,262 by stars
ChartLatestAffected imagesRadar Score
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
perl@5.18.2-2ubuntu1
no fix listed

Open the chart page →

41,427
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

7,835
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
typesense/typesense:28.0.rc35dea1b62b7b6e
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

10,090
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

9,783
backendzymtraceOfficialVerified publisher26.9.11 of 6See more

backend zymtrace 26.9.1

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/postgres:17.4304ab8135187
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

10,323
acos-prometheus-exporter-helm-charta10-prometheus-exporter0.1.01 of 1See more

acos-prometheus-exporter-helm-chart a10-prometheus-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
a10networks/acos-prometheus-exporter:latest8dc58d434d71
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

12,007
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,554
open5gsadaptivenetlabVerified publisher1.0.32 of 3See more

open5gs adaptivenetlab 1.0.3

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
free5gmano/nextepc-mongodb:latest36f806935519
perl@5.22.1-9ubuntu0.6
no fix listed
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

25,443
bootaerokube1.0.12 of 4See more

boot aerokube 1.0.1

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/aerokube/jumphost:1.0.170fd7c00418d
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
quay.io/aerokube/keygen:1.0.1578934444f04
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

7,834
msockperfaetrius2.0.82 of 2See more

msockperf aetrius 2.0.8

2 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

4,159
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,922
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v172035434f455
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

9,321
akto-regional-setupakto1.3.11 of 9See more

akto-regional-setup akto 1.3.1

1 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.072035434f455
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

7,603
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

6,324
katalogalpineworks0.1.21 of 5See more

katalog alpineworks 0.1.2

1 of the 5 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

4,497
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,190
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

28,131
anchore-admission-controlleranchore-charts0.8.41 of 2See more

anchore-admission-controller anchore-charts 0.8.4

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

7,852
pagesandrei-pages1.0.02 of 3See more

pages andrei-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
perl@5.30.0-9ubuntu0.2
no fix listed
flyway/flyway:6.4.422d97ceb0c47
perl@5.26.1-6ubuntu0.3
no fix listed

Open the chart page →

20,190
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
perl@5.26.1-6ubuntu0.7
no fix listed

Open the chart page →

11,553
games-on-whalesangelnu2.0.04 of 7See more

games-on-whales angelnu 2.0.0

4 of the 7 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
perl@5.30.0-9ubuntu0.2
no fix listed
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

42,126
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

25,669
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

6,187
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

19,745
inbox-server-distributedappscodeVerified publisher2025.12.252 of 4See more

inbox-server-distributed appscode 2025.12.25

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
library/rabbitmq:3.12.1-managementf020c06da226
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.03 of 4See more

james-kompose appscode 0.1.0

3 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
library/rabbitmq:3.12.1-managementf020c06da226
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

16,975
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

3,270
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

5,657
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
perl@5.38.2-3.2ubuntu0.1
5.38.2-3.2ubuntu0.2

Open the chart page →

7,300
arlas-aiasarlas-stackVerified publisher28.8.09 of 22See more

arlas-aias arlas-stack 28.8.0

9 of the 22 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3

Open the chart page →

40,238
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

23,353
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
perl@5.30.0-9ubuntu0.5
no fix listed

Open the chart page →

3,530
keystonearzu0.2.293 of 4See more

keystone arzu 0.2.29

3 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/rabbitmq:3.7-managementb6dd45cc35b3
perl@5.26.1-6ubuntu0.3
no fix listed
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
perl@5.30.0-9ubuntu0.4
no fix listed
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
perl@5.30.0-9ubuntu0.4
no fix listed

Open the chart page →

22,568
dltkvassist-iot-data-integrity-verification0.2.02 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

2 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
perl@5.22.1-9ubuntu0.5
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.02 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

2 of the 9 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
perl@5.22.1-9ubuntu0.5
no fix listed
hyperledger/fabric-couchdb:0.4.15f6c724592abf
perl@5.22.1-9ubuntu0.6
no fix listed

Open the chart page →

77,706
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

9,369
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
perl@5.36.0-7
5.36.0-7+deb12u3

Open the chart page →

13,352
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5

Open the chart page →

10,061
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

18,277
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
perl@5.30.0-9ubuntu0.2
no fix listed

Open the chart page →

7,936
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

5,363
smartorchestratorassist-iot-smart-orchestrator4.0.04 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

4 of the 14 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
perl@5.36.0-7
5.36.0-7+deb12u3
library/mongo:4.4.66efa05203990
perl@5.26.1-6ubuntu0.5
no fix listed

Open the chart page →

45,363
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
perl@5.30.0-9ubuntu0.3
no fix listed

Open the chart page →

13,913
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

32,501
auctioneerastria0.0.21 of 1See more

auctioneer astria 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,178
evm-bridge-withdrawerastria1.0.61 of 1See more

evm-bridge-withdrawer astria 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

2,154
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

3,680
graph-nodeastria0.2.21 of 3See more

graph-node astria 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
graphprotocol/graph-node:latestb0436347fb24
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3

Open the chart page →

5,495
hermesastria0.7.11 of 1See more

hermes astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
perl@5.38.2-3.2build2
5.38.2-3.2ubuntu0.2

Open the chart page →

1,952
hyperlane-agentsastria0.1.41 of 2See more

hyperlane-agents astria 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-40909.

Container imageDigestPackageFixed in
gcr.io/abacus-labs-dev/hyperlane-agent:10c0ab1-20231215-220639f33e88324a40
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5

Open the chart page →

2,498

Container images carrying it

1,319 by charts deploying them

A fixed version is listed for 41 of the 41 affected packages.

Container imageDigestPackageFixed inUsed by
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ddosify/selfhosted_backend:3.2.93c11e3182652
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
deconzcommunity/deconz:2.29.2062de2362641
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
perl@5.30.0-9ubuntu0.2
no fix listed
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
defactops/defactops-backend:1.0.2307b663c0092a
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
dellcloud/category:distributed02fc234353a9
perl@5.30.0-9ubuntu0.2
no fix listed
1
dellcloud/pages:1.04d2eb25b9225
perl@5.30.0-9ubuntu0.2
no fix listed
1
devopsgoofy/k8s-platform:latestad865312099f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
perl@5.30.0-9ubuntu0.2
no fix listed
1
djjudas21/alertify:0.1.0ba22be670c37
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
dniel/api-posts:master45a667852f2a
perl@5.26.1-6ubuntu0.3
no fix listed
1
dobtc/bitcoin:25.1a870f7cb1105
perl@5.36.0-7
5.36.0-7+deb12u3
1
domainmod/domainmod:4.23.04017bfe4c597
perl@5.36.0-7
5.36.0-7+deb12u3
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
perl@5.30.0-9ubuntu0.5
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
dremio/dremio-oss:24.1.080ed2e3b7c43
perl@5.34.0-3ubuntu1.1
5.34.0-3ubuntu1.5
1
drorivry4/rego:lateste035d49b15ca
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
drpcorg/dshackle:0.54.08858fae1859d
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
dserio83/velero-api:0.3.16b3d9115fee2
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
dserio83/velero-watchdog:0.1.8d5deae589229
perl@5.36.0-7+deb12u2
5.36.0-7+deb12u3
1
duck1123/cert-downloader:latest0e29f19fa67c
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
duck1123/lnd-fileserver:latest9d6fb247b714
perl@5.34.0-3ubuntu1.2
5.34.0-3ubuntu1.5
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
elastic/apm-server:7.17.6c7a1c63257d0
perl@5.30.0-9ubuntu0.2
no fix listed
1
elastictranscoder/media:627e21dc963ab3858c6b
perl@5.26.1-6ubuntu0.3
no fix listed
1
elastictranscoder/media-storage:f6d861a026208b8c2359
perl@5.26.1-6ubuntu0.3
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
perl@5.26.1-6ubuntu0.3
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
perl@5.26.1-6ubuntu0.3
no fix listed
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
perl@5.30.0-9ubuntu0.2
no fix listed
1
emqx/ecp-ui:2.5.1e33e9816f147
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
enclavenetworks/enclave:latest0a99759300d1
perl@5.30.0-9ubuntu0.5
no fix listed
1
engrmth/bnkr:2.1.06d8464e6f0e8
perl@5.30.0-9ubuntu0.2
no fix listed
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
perl@5.26.1-6ubuntu0.5
no fix listed
1
envoyproxy/envoy:v1.30.92956bd9de830
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.33.056da5afd7df3
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.31-latestcaa5b411be16
perl@5.34.0-3ubuntu1.4
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.30.1e596fda6a0ce
perl@5.34.0-3ubuntu1.3
5.34.0-3ubuntu1.5
1
envoyproxy/envoy:v1.18.2e8b37c1d7578
perl@5.26.1-6ubuntu0.5
no fix listed
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
perl@5.26.1-6ubuntu0.6
no fix listed
1
erigontech/erigon:v2.61.288706754b627
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
esphome/esphome:2024.3.09ab8cc88b28c
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
esphome/esphome:2024.12.2b2c6322700ac
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
esphome/esphome:2025.3.0def8b6e4f517
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
perl@5.30.0-9ubuntu0.2
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
perl@5.22.1-9ubuntu0.2
no fix listed
1
ethersphere/bee:2.2.0a884fd84b72f
perl@5.36.0-7+deb12u1
5.36.0-7+deb12u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.