StackRadar

CVE-2026-26740

High

Advisory

Published 18 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
85
of 17,781 indexed, latest versions
Container images
79
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: giflib security update

Carried by container images the latest versions of 85 of 17,781 indexed charts deploy, on 79 images.

Affected packageAffected versionsFixed inImages
giflibdeb5.1.4-0.3~16.04, 5.1.4-0.3~16.04.1, 5.1.4-2, 5.1.4-2ubuntu0.1+8 more5.1.9-2ubuntu0.3, 5.2.1-2.5+deb12u1, 5.2.2-1+deb13u1, 5.2.2-1ubuntu1.2+1 more65
giflibrpm5.1.4-3.el8, 5.2.1-9.el90:5.1.4-3.el8_4.2, 0:5.1.4-3.el8_6.2, 0:5.1.4-5.el8_10, 0:5.2.1-9.el9_4.214
OSV records
DEBIAN-CVE-2026-26740RHSA-2026:33450RHSA-2026:33452RHSA-2026:33455RHSA-2026:33503UBUNTU-CVE-2026-26740
Also known as
RHSA-2026:33501, USN-8583-1

Charts affected

85 by stars
ChartLatestAffected imagesRadar Score
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
giflib@5.1.4-2ubuntu0.1
no fix listed

Open the chart page →

26,944
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
giflib@5.1.4-2ubuntu0.1
no fix listed

Open the chart page →

10,627
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
giflib@5.1.9-2build2
5.1.9-2ubuntu0.3

Open the chart page →

14,290
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
giflib@5.2.1-2.5
5.2.1-2.5+deb12u1

Open the chart page →

16,384
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2

Open the chart page →

45,239
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
giflib@5.2.1-2.5
5.2.1-2.5+deb12u1

Open the chart page →

10,780
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
giflib@5.1.4-3.el8
0:5.1.4-5.el8_10

Open the chart page →

12,856
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2

Open the chart page →

6,586
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2

Open the chart page →

6,568
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2

Open the chart page →

8,811
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
giflib@5.2.2-1+b1
5.2.2-1+deb13u1

Open the chart page →

9,103
chaos-meshkubeblocksVerified publisher2.7.21 of 4See more

chaos-mesh kubeblocks 2.7.2

1 of the 4 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
giflib@5.2.1-2.5
5.2.1-2.5+deb12u1

Open the chart page →

13,497
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
giflib@5.1.9-2ubuntu0.1
5.1.9-2ubuntu0.3

Open the chart page →

16,877
tinymediamanagermedia-servarrVerified publisher1.6.21 of 2See more

tinymediamanager media-servarr 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
giflib@5.2.2-1+b1
5.2.2-1+deb13u1

Open the chart page →

7,944
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
giflib@5.2.2-1+b1
5.2.2-1+deb13u1

Open the chart page →

11,950
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
giflib@5.1.9-2build2
5.1.9-2ubuntu0.3

Open the chart page →

12,791
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
giflib@5.1.9-2build2
5.1.9-2ubuntu0.3

Open the chart page →

12,791
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
giflib@5.1.4-3.el8
0:5.1.4-5.el8_10

Open the chart page →

9,149
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
giflib@5.1.9-1
no fix listed

Open the chart page →

109,294
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
giflib@5.1.9-1
no fix listed

Open the chart page →

22,658
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
giflib@5.1.4-2ubuntu0.1
no fix listed

Open the chart page →

27,633
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
giflib@5.1.4-2
no fix listed

Open the chart page →

63,223
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
giflib@5.1.9-1
no fix listed

Open the chart page →

15,520
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
giflib@5.1.4-3.el8
0:5.1.4-3.el8_4.2

Open the chart page →

29,227
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
giflib@5.2.2-1+b1
5.2.2-1+deb13u1

Open the chart page →

10,605
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2

Open the chart page →

6,207
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
giflib@5.2.2-1ubuntu3
5.2.2-1ubuntu3.2

Open the chart page →

10,348
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
giflib@5.1.4-3.el8
0:5.1.4-3.el8_4.2

Open the chart page →

28,165
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
giflib@5.1.4-3.el8
0:5.1.4-3.el8_6.2

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
giflib@5.1.4-3.el8
0:5.1.4-3.el8_6.2

Open the chart page →

11,554
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2

Open the chart page →

12,460
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
giflib@5.1.4-3.el8
0:5.1.4-3.el8_4.2

Open the chart page →

12,455
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2

Open the chart page →

45,239
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-26740.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
giflib@5.1.4-3.el8
0:5.1.4-5.el8_10

Open the chart page →

11,577

Container images carrying it

79 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
giflib@5.1.4-3.el8
0:5.1.4-5.el8_10
1
wavefronthq/proxy:9.2d1064d28f6eb
giflib@5.1.4-2ubuntu0.1
no fix listed
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
giflib@5.2.1-2.5
5.2.1-2.5+deb12u1
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
giflib@5.2.1-2.5
5.2.1-2.5+deb12u1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
giflib@5.2.1-2.5
5.2.1-2.5+deb12u1
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
giflib@5.2.1-2.5
5.2.1-2.5+deb12u1
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
giflib@5.1.9-1
no fix listed
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
giflib@5.1.4-3.el8
0:5.1.4-5.el8_10
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
giflib@5.1.9-2build2
5.1.9-2ubuntu0.3
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
giflib@5.1.4-2ubuntu0.1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
giflib@5.2.1-2.5
5.2.1-2.5+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
giflib@5.2.2-1+b1
5.2.2-1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
giflib@5.2.2-1+b1
5.2.2-1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
giflib@5.2.2-1+b1
5.2.2-1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
giflib@5.2.1-2.5
5.2.1-2.5+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
giflib@5.2.2-1+b1
5.2.2-1+deb13u1
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
giflib@5.1.9-1
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
giflib@5.1.4-3.el8
0:5.1.4-3.el8_4.2
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
giflib@5.1.4-3.el8
0:5.1.4-3.el8_6.2
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
giflib@5.1.4-3.el8
0:5.1.4-5.el8_10
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
giflib@5.1.4-3.el8
0:5.1.4-3.el8_6.2
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
giflib@5.1.4-3.el8
0:5.1.4-3.el8_6.2
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
giflib@5.1.4-3.el8
0:5.1.4-5.el8_10
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
giflib@5.1.4-0.3~16.04.1
no fix listed
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
giflib@5.1.4-3.el8
0:5.1.4-3.el8_4.2
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
giflib@5.2.2-1ubuntu1
5.2.2-1ubuntu1.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.