StackRadar

CVE-2026-4775

High

Advisory

Published 24 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
351
of 17,781 indexed, latest versions
Container images
371
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libtiff security update

Carried by container images the latest versions of 351 of 17,781 indexed charts deploy, on 371 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+43 more4.5.0-6+deb12u4, 4.7.0-3+deb13u2349
libtiffrpm4.0.3-32.el7, 4.0.9-17.el8, 4.0.9-18.el8, 4.0.9-28.el8_8+4 more0:4.0.3-35.el7_9.2, 0:4.0.9-37.el8_10, 0:4.4.0-15.el9_7.322
OSV records
DEBIAN-CVE-2026-4775RHSA-2026:12271RHSA-2026:16055RHSA-2026:25910UBUNTU-CVE-2026-4775
Also known as
RHSA-2026:19363, RHSA-2026:19604, RHSA-2026:19659, RHSA-2026:19702

Charts affected

351 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-4775.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tiff@4.3.0-6ubuntu0.13
no fix listed

Open the chart page →

7,849

Container images carrying it

371 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
tiff@4.1.0+git191117-2ubuntu0.20.04.2
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
1
camptocamp/mapserver:latestbf2e8e118c9b
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
castopod/castopod:1.12.101fd37280cbb2
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
castopod/castopod:1.15.54e4f0440520f
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
tiff@4.3.0-6ubuntu0.13
no fix listed
1
cheyang/distributed-tf:1.6.046cc34755493
tiff@4.0.6-1ubuntu0.2
no fix listed
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
ckulka/baikal:0.10.1-nginx434bdd162247
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
codetogether/codetogether:latest4348c8a38752
libtiff@4.4.0-12.el9
0:4.4.0-15.el9_7.3
1
countly/countly-server:25.05.4e3c238248f99
tiff@4.1.0+git191117-2ubuntu0.20.04.13
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
tiff@4.5.0-6
4.5.0-6+deb12u4
1
dannielkil/book-frontend:latest937993927694
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
daskdev/dask-notebook:1.1.0052630f5ca04
tiff@4.0.9-5ubuntu0.1
no fix listed
1
datamate/seafile-professional:11.0.202dd66b722464
tiff@4.3.0-6ubuntu0.11
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
tiff@4.1.0+git191117-2ubuntu0.20.04.3
no fix listed
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
tiff@4.7.0-3
4.7.0-3+deb13u2
1
dragonflyoss/client:v0.1.82edf3e921f4e0
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
tiff@4.0.9-5ubuntu0.4
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
tiff@4.0.9-5ubuntu0.4
no fix listed
1
emqx/ecp-ui:2.5.1e33e9816f147
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
felipecs8/app-db-connection-test:v129e06c9c6385
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
firefart/requesttracker:5.0.40d6249906d8c
tiff@4.5.0-6
4.5.0-6+deb12u4
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
tiff@4.1.0+git191117-2ubuntu0.20.04.14
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
fluent/fluent-bit:4.0-debuge76397ef3983
tiff@4.5.0-6+deb12u3
4.5.0-6+deb12u4
1
fnzv/dump1090:latestb3079b95c336
tiff@4.3.0-6ubuntu0.7
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
tiff@4.0.3-7ubuntu0.9
no fix listed
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
tiff@4.3.0-6ubuntu0.13
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
tiff@4.0.9-5ubuntu0.3
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
tiff@4.3.0-6ubuntu0.10
no fix listed
1
gotenberg/gotenberg:8.30206a6c708fc6
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
gurolakman/oam:4.0.0ed8fd2062548
libtiff@4.0.9-32.el8_10
0:4.0.9-37.el8_10
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
libtiff@4.0.9-29.el8_8
0:4.0.9-37.el8_10
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
libtiff@4.0.9-29.el8_8
0:4.0.9-37.el8_10
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
libtiff@4.0.9-29.el8_8
0:4.0.9-37.el8_10
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
libtiff@4.0.9-29.el8_8
0:4.0.9-37.el8_10
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
libtiff@4.0.9-29.el8_8
0:4.0.9-37.el8_10
1
gurolakman/ussigw-core:1.0.48739565c3ea2
libtiff@4.0.9-29.el8_8
0:4.0.9-37.el8_10
1
haveagitgat/tdarr:2.00.181256348872ce
tiff@4.1.0+git191117-2ubuntu0.20.04.2
no fix listed
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
tiff@4.1.0+git191117-2build1
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
tiff@4.1.0+git191117-2ubuntu0.20.04.9
no fix listed
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
hazegoodlife/haaze:milksite8d4c63169e14
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.