StackRadar

CVE-2026-36849

Medium

Advisory

Published 17 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
566
of 17,781 indexed, latest versions
Container images
452
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 566 of 17,781 indexed charts deploy, on 452 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+46 moreno fix listed452
OSV records
UBUNTU-CVE-2026-36849DEBIAN-CVE-2026-36849

Charts affected

566 by stars
ChartLatestAffected imagesRadar Score
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed

Open the chart page →

113,791
ohifkylesferrazzaVerified publisher0.1.01 of 2See more

ohif kylesferrazza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
jodogne/orthanc-plugins:latest6ff510aa29c2
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

3,512
overpass-apil4gVerified publisher0.1.21 of 1See more

overpass-api l4g 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
wiktorn/overpass-api:latest9bb5f4a9b54c
tiff@4.5.0-6+deb12u4
no fix listed

Open the chart page →

3,544
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
langflowai/langflow-frontend:latest54f67f1961fe
tiff@4.5.0-6+deb12u3
no fix listed

Open the chart page →

3,980
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
tiff@4.5.0-6+deb12u2
no fix listed

Open the chart page →

35,050
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
tiff@4.5.0-6+deb12u3
no fix listed

Open the chart page →

7,201
flaresolverrm0nsterrr-flaresolverrVerified publisher2.4.11 of 1See more

flaresolverr m0nsterrr-flaresolverr 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.5.2c80ae007ce2c
tiff@4.5.0-6+deb12u4
no fix listed

Open the chart page →

6,136
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
tiff@4.5.0-6+deb12u1
no fix listed

Open the chart page →

5,734
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
tiff@4.7.0-3ubuntu3
no fix listed

Open the chart page →

11,103
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
tiff@4.5.0-6+deb12u2
no fix listed

Open the chart page →

13,738
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
tiff@4.7.0-3+deb13u2
no fix listed

Open the chart page →

7,527
12factormyaVerified publisher24.1.21 of 1See more

12factor mya 24.1.2

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

1,827
my-react-appmy-react-app0.1.51 of 1See more

my-react-app my-react-app 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

1,827
nginx-chartnginx-chart-testVerified publisher0.1.11 of 1See more

nginx-chart nginx-chart-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

1,827
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

14,250
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
tiff@4.5.0-6+deb12u1
no fix listed

Open the chart page →

5,039
onechartonechart-slVerified publisher0.76.01 of 1See more

onechart onechart-sl 0.76.0

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

1,827
opencatalogiopencatalogi1.0.62 of 8See more

opencatalogi opencatalogi 1.0.6

2 of the 8 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
tiff@4.5.0-6
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
tiff@4.5.0-6+deb12u1
no fix listed

Open the chart page →

14,838
opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest26da43bb5b66
tiff@4.3.0-6ubuntu0.13
no fix listed
shaowenchen/ops-server:latest315444f703f4
tiff@4.3.0-6ubuntu0.11
no fix listed

Open the chart page →

8,939
paperless-ngxpaperlessVerified publisher0.4.01 of 3See more

paperless-ngx paperless 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngxdigest-pinnedaa810a36942c
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

8,489
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
tiff@4.7.0-3+deb13u2
no fix listed

Open the chart page →

7,035
playgroundplayground0.1.11 of 1See more

playground playground 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

1,827
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
tiff@4.5.0-6+deb12u2
no fix listed

Open the chart page →

31,844
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed

Open the chart page →

23,964
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest1336a777f9a4
tiff@4.3.0-6ubuntu0.10
no fix listed

Open the chart page →

7,405
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

4,240
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
tiff@4.5.0-6+deb12u4
no fix listed

Open the chart page →

5,482
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
tiff@4.5.0-6+deb12u3
no fix listed

Open the chart page →

7,740
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
tiff@4.3.0-6ubuntu0.13
no fix listed

Open the chart page →

12,930
rstudio-pmrstudioVerified publisher0.20.51 of 1See more

rstudio-pm rstudio 0.20.5

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed

Open the chart page →

1,324
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
tiff@4.5.0-6+deb12u2
no fix listed

Open the chart page →

5,315
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
tiff@4.0.9-5ubuntu0.4
no fix listed

Open the chart page →

13,541
kyoorubxkubeVerified publisher0.1.102 of 9See more

kyoo rubxkube 0.1.10

2 of the 9 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
tiff@4.5.0-6+deb12u1
no fix listed
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
tiff@4.5.0-6+deb12u1
no fix listed

Open the chart page →

30,234
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
tiff@4.5.0-6+deb12u3
no fix listed

Open the chart page →

38,107
immichsecustorVerified publisher2.0.41 of 1See more

immich secustor 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

3,059
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/getsentry/taskbroker:26.7.264d0da74a578
tiff@4.5.0-6+deb12u4
no fix listed

Open the chart page →

16,449
smarter-demosmarterOfficialVerified publisher0.1.52 of 7See more

smarter-demo smarter 0.1.5

2 of the 7 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
tiff@4.1.0+git191117-2ubuntu0.20.04.5
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
tiff@4.1.0+git191117-2ubuntu0.20.04.5
no fix listed

Open the chart page →

45,832
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
tiff@4.7.0-3+deb13u1
no fix listed

Open the chart page →

7,126
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
tiff@4.5.0-6+deb12u1
no fix listed

Open the chart page →

5,676
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
tiff@4.5.0-6+deb12u2
no fix listed

Open the chart page →

10,380
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
tiff@4.7.0-3+deb13u2
no fix listed

Open the chart page →

3,240
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

1,827
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

1,827
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
tiff@4.5.0-6+deb12u2
no fix listed

Open the chart page →

12,581
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
tiff@4.1.0+git191117-2ubuntu0.20.04.9
no fix listed
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
tiff@4.1.0+git191117-2ubuntu0.20.04.3
no fix listed

Open the chart page →

26,657
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
tiff@4.7.0-3+deb13u1
no fix listed

Open the chart page →

7,696
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
tiff@4.7.0-3+deb13u2
no fix listed

Open the chart page →

8,217
changedetection-iozekker6Verified publisher1.99.01 of 1See more

changedetection-io zekker6 1.99.0

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.47bb6963b730d
tiff@4.5.0-6+deb12u4
no fix listed

Open the chart page →

2,595
gotenbergadnoctemVerified publisher0.5.01 of 1See more

gotenberg adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.37.0f29984bd1e22
tiff@4.7.0-3+deb13u3
no fix listed

Open the chart page →

5,582
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-36849.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
tiff@4.5.0-6+deb12u4
no fix listed

Open the chart page →

30,028

Container images carrying it

452 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
moreillon/user-manager-front:v5.1.06597e6b98d21
tiff@4.5.0-6+deb12u1
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
tiff@4.5.0-6
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
tiff@4.5.0-6+deb12u1
no fix listed
1
nethermind/nethermind:1.14.615517708c3b6
tiff@4.3.0-6ubuntu0.2
no fix listed
1
netskopeprivateaccess/publisher_u22:latest93e2fd164a93
tiff@4.3.0-6ubuntu0.13
no fix listed
1
nginxinc/nginx-unprivileged:latest4210a3296e7c
tiff@4.7.0-3+deb13u3
no fix listed
1
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
tiff@4.7.0-3+deb13u2
no fix listed
1
nginx/nginx-ingress:edge520d439f9a9a
tiff@4.7.0-3+deb13u3
no fix listed
1
nginx/nginx-ingress:5.6.18ca7b42ae702
tiff@4.7.0-3+deb13u3
no fix listed
1
nirmalnaveen/supermario:latest8541a39162f3
tiff@4.5.0-6
no fix listed
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
tiff@4.7.0-3+deb13u3
no fix listed
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
tiff@4.0.9-5ubuntu0.2
no fix listed
1
oneuptime/probe:release6b2d98713711
tiff@4.5.0-6+deb12u4
no fix listed
1
oneuptime/runner:release4accc516d800
tiff@4.7.0-3+deb13u3
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
tiff@4.5.0-6+deb12u1
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
tiff@4.5.0-6+deb12u1
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
tiff@4.5.0-6+deb12u1
no fix listed
1
opea/speecht5:1.0249afad3d268
tiff@4.5.0-6+deb12u1
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
tiff@4.5.0-6+deb12u2
no fix listed
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
tiff@4.5.0-6+deb12u4
no fix listed
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
tiff@4.7.0-3+deb13u3
no fix listed
1
opendatacube/explorer:latest120457ffcd69
tiff@4.5.1+git230720-4ubuntu2.3
no fix listed
1
opendatacube/pipelines:wofs-1.225d810e8504b8
tiff@4.0.9-5ubuntu0.2
no fix listed
1
opendatacube/restcube:latest91870111837c
tiff@4.0.9-5ubuntu0.2
no fix listed
1
opendatacube/wms:latest1b90cdf68831
tiff@4.0.9-5ubuntu0.2
no fix listed
1
opendatacube/wps:latest80df355a660b
tiff@4.3.0-6ubuntu0.10
no fix listed
1
openelevation/open-elevation:latest82fb21612e86
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
1
openkm/openkm-ce:6.3.113bc465a7461b
tiff@4.1.0+git191117-2ubuntu0.20.04.3
no fix listed
1
openproject/hocuspocus:release-338001b288dc1359dfb5
tiff@4.5.0-6+deb12u2
no fix listed
1
openproject/openproject:17.8.0-slim48952034215d
tiff@4.7.0-3+deb13u3
no fix listed
1
opsmx11/issuegen:v2.1.05c50ca123d88
tiff@4.0.3-7ubuntu0.9
no fix listed
1
owncloud/server:10.15.051d9b74fc2a8
tiff@4.1.0+git191117-2ubuntu0.20.04.13
no fix listed
1
owncloud/server:10.16.274c53d341076
tiff@4.3.0-6ubuntu0.13
no fix listed
1
owncloud/server:10.16.3b3f9efdcd7f7
tiff@4.3.0-6ubuntu0.13
no fix listed
1
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
tiff@4.7.0-3+deb13u2
no fix listed
1
penpotapp/backend:2.2.147853d9bb9dd
tiff@4.3.0-6ubuntu0.10
no fix listed
1
penpotapp/exporter:2.2.15c835ffd87ab
tiff@4.3.0-6ubuntu0.10
no fix listed
1
penpotapp/exporter:2.17.272a8061e8806
tiff@4.7.0-3ubuntu5
no fix listed
1
phan2410/dummy-service:0.0.89c6ed6de26ca
tiff@4.5.0-6+deb12u2
no fix listed
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
tiff@4.5.0-6+deb12u2
no fix listed
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
tiff@4.3.0-6ubuntu0.7
no fix listed
1
photoprism/photoprism:220629-jammy2954334adbda
tiff@4.3.0-6
no fix listed
1
photoprism/photoprism:260601650c6ad5a651
tiff@4.7.0-3ubuntu4
no fix listed
1
photoprism/photoprism:260728958642220223
tiff@4.7.0-3ubuntu4
no fix listed
1
photoprism/photoprism:251130db16ee6b1ba3
tiff@4.7.0-3ubuntu3
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
tiff@4.5.1+git230720-4ubuntu2.1
no fix listed
1
pk910/powfaucet:v2-stable3dcae6a62896
tiff@4.5.0-6+deb12u2
no fix listed
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
postgis/postgis:18-3.67e00e8c3539f
tiff@4.7.0-3+deb13u3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.