CVE-2026-12912
HighAdvisory
Published 29 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.3
- base score, highest
- EPSS
- 0.004
- 37th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 420
- of 17,787 indexed, latest versions
- Container images
- 430
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Red Hat Security Advisory: libtiff security update
Carried by container images the latest versions of 420 of 17,787 indexed charts deploy, on 430 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| tiffdeb | 4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+45 more | 4.7.0-3+deb13u3 | 408 |
| libtiffrpm | 4.0.9-17.el8, 4.0.9-18.el8, 4.0.9-28.el8_8, 4.0.9-29.el8_8+4 more | 0:4.0.9-38.el8_10, 0:4.4.0-18.el9_8.1 | 22 |
- OSV records
- DEBIAN-CVE-2026-12912RHSA-2026:42668RHSA-2026:47184UBUNTU-CVE-2026-12912
- Also known as
- RHSA-2026:58553, RHSA-2026:58556
Charts affected
420 by stars
Container images carrying it
430 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| timothyclarke/ | 22c41e5ca7e2 | tiff | no fix listed | 1 |
| tinymediamanager/ | 2b34dc85099e | tiff | 4.7.0-3+deb13u3 | 1 |
| treskon/ | a475d80e4ecf | tiff | no fix listed | 1 |
| trueosiris/ | 9356f98ad561 | tiff | no fix listed | 1 |
| twentycrm/ | 2f78405a78be | tiff | no fix listed | 1 |
| unitycatalog/ | 3a688197b218 | tiff | no fix listed | 1 |
| vinanrra/ | f9534490bd2b | tiff | no fix listed | 1 |
| vlebediantsev/ | 007c6670ff48 | tiff | no fix listed | 1 |
| vlebediantsev/ | 945675fd2636 | tiff | no fix listed | 1 |
| vlebediantsev/ | 54f69d116c50 | tiff | no fix listed | 1 |
| wiktorn/ | 9bb5f4a9b54c | tiff | no fix listed | 1 |
| workadventure/ | 92b664c2a06f | tiff | no fix listed | 1 |
| xeladock/ | 4baf531453f1 | tiff | no fix listed | 1 |
| xeladock/ | c259a67b1dff | tiff | no fix listed | 1 |
| xom4ekp2p/ | d0e0aa238b02 | tiff | no fix listed | 1 |
| xom4ekp2p/ | 2745b5fd8785 | tiff | no fix listed | 1 |
| zabbix/ | 0e5f69c4c54e | tiff | no fix listed | 1 |
| zabbix/ | 01de79c31391 | tiff | no fix listed | 1 |
| zabbix/ | 7d4d58086515 | tiff | no fix listed | 1 |
| zabbix/ | 99e9a090b516 | tiff | no fix listed | 1 |
| zabbix/ | 915b3183e054 | tiff | no fix listed | 1 |
| zabbix/ | ee4baa872280 | tiff | no fix listed | 1 |
| zooproject/ | 9a507cb7e2dd | tiff | no fix listed | 1 |
| gcr.io/ | 9bcfd2abc361 | tiff | no fix listed | 1 |
| ghcr.io/ | 766699daa9ac | tiff | no fix listed | 1 |
| ghcr.io/ | d332ae2410f8 | tiff | no fix listed | 1 |
| ghcr.io/ | f9104080d9a7 | tiff | 4.7.0-3+deb13u3 | 1 |
| ghcr.io/ | 5889bea38e56 | tiff | no fix listed | 1 |
| ghcr.io/ | d600eac6283f | tiff | no fix listed | 1 |
| ghcr.io/ | ca7dc7362968 | tiff | no fix listed | 1 |
| ghcr.io/ | 0e99f12bb040 | tiff | no fix listed | 1 |
| ghcr.io/ | a058034ca006 | tiff | no fix listed | 1 |
| ghcr.io/ | fb609bc264d9 | tiff | no fix listed | 1 |
| ghcr.io/ | 726a947bb65b | tiff | no fix listed | 1 |
| ghcr.io/ | 246dc2160efe | tiff | 4.7.0-3+deb13u3 | 1 |
| ghcr.io/ | 76771c3cc8c3 | tiff | no fix listed | 1 |
| ghcr.io/ | a2be95de450c | tiff | 4.7.0-3+deb13u3 | 1 |
| ghcr.io/ | 16fda01ae58a | tiff | no fix listed | 1 |
| ghcr.io/ | 609f48af4efc | tiff | 4.7.0-3+deb13u3 | 1 |
| ghcr.io/ | 3225d2bc6b3c | tiff | 4.7.0-3+deb13u3 | 1 |
| ghcr.io/ | f53bde3acd4f | tiff | no fix listed | 1 |
| ghcr.io/ | bffe3c22fabc | tiff | 4.7.0-3+deb13u3 | 1 |
| ghcr.io/ | e59ebde55709 | tiff | 4.7.0-3+deb13u3 | 1 |
| ghcr.io/ | 7bb6963b730d | tiff | no fix listed | 1 |
| ghcr.io/ | 6e82914e1051 | tiff | no fix listed | 1 |
| ghcr.io/ | ab535d1fef5d | tiff | no fix listed | 1 |
| ghcr.io/ | 64d0da74a578 | tiff | no fix listed | 1 |
| ghcr.io/ | 472a25038957 | tiff | no fix listed | 1 |
| ghcr.io/ | 3fbe4c29d14c | tiff | no fix listed | 1 |
| ghcr.io/ | 8e53861be292 | tiff | no fix listed | 1 |