StackRadar

CVE-2026-4775

High

Advisory

Published 24 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
351
of 17,781 indexed, latest versions
Container images
371
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libtiff security update

Carried by container images the latest versions of 351 of 17,781 indexed charts deploy, on 371 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+43 more4.5.0-6+deb12u4, 4.7.0-3+deb13u2349
libtiffrpm4.0.3-32.el7, 4.0.9-17.el8, 4.0.9-18.el8, 4.0.9-28.el8_8+4 more0:4.0.3-35.el7_9.2, 0:4.0.9-37.el8_10, 0:4.4.0-15.el9_7.322
OSV records
DEBIAN-CVE-2026-4775RHSA-2026:12271RHSA-2026:16055RHSA-2026:25910UBUNTU-CVE-2026-4775
Also known as
RHSA-2026:19363, RHSA-2026:19604, RHSA-2026:19659, RHSA-2026:19702

Charts affected

351 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-4775.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tiff@4.3.0-6ubuntu0.13
no fix listed

Open the chart page →

7,849

Container images carrying it

371 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hazelcast/management-center:5.3.2f9d34300d330
libtiff@4.0.9-28.el8_8
0:4.0.9-37.el8_10
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
tiff@4.5.0-6
4.5.0-6+deb12u4
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
tiff@4.0.9-5ubuntu0.3
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
tiff@4.0.6-1ubuntu0.4
no fix listed
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
libtiff@4.0.3-32.el7
0:4.0.3-35.el7_9.2
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
libtiff@4.0.3-32.el7
0:4.0.3-35.el7_9.2
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
libtiff@4.0.3-32.el7
0:4.0.3-35.el7_9.2
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
tiff@4.1.0+git191117-2ubuntu0.20.04.3
no fix listed
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
tiff@4.1.0+git191117-2ubuntu0.20.04.3
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ispras/svacer:11-2-042aa9fa9f189
tiff@4.3.0-6ubuntu0.10
no fix listed
1
itzg/bungeecord:latest1c59f9631f3b
tiff@4.7.0-3ubuntu5
no fix listed
1
itzg/minecraft-server:2026.9.04e29d14082d9
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
itzg/minecraft-server:latest8672e335dbef
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
jaedb/iris:latest048cfbf58d57
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
knspar/phronetis-operator:0.1.60c4f0543ee58
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
kong/httpbin:latesta6ac46531193
tiff@4.3.0-6ubuntu0.10
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
tiff@4.3.0-6ubuntu0.10
no fix listed
1
kuzwolka/aws9:main1ad759b961b1
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
kuzwolka/aws9:news3e8880fbbb96
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
kuzwolka/aws9:blog4a7707410bf1
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
kuzwolka/aws9:shop84a9d9766345
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
laly9999/node-app:1dd0e503913e1
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
langflowai/langflow-frontend:latest54f67f1961fe
tiff@4.5.0-6+deb12u3
4.5.0-6+deb12u4
1
langgenius/dify-api:0.6.11fca918260dd6
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
tiff@4.5.1+git230720-4ubuntu2.4
no fix listed
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
library/nextcloud:31.0.6-apache588609d76b21
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
library/nextcloud:31.0.10-apacheb7faa1653c39
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
library/nginx:1.27.409369da6b103
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
library/nginx:1.276784fb0834aa
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
library/nginx:1.25.167f9a4f10d14
tiff@4.5.0-6
4.5.0-6+deb12u4
1
library/nginx:1.25.49ff236ed47fe
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
library/nginx:1.27.3fb197595ebe7
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
library/python:3.8d41127070014
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
library/python:3.9da5aee29682d
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
library/wordpress:6.4.3-apache8ae66efb09a2
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
library/wordpress:php8.1-apachef73396626d2f
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
tiff@4.0.9-5ubuntu0.4
no fix listed
1
linuxserver/calibre-web:0.6.24241009026e6f
tiff@4.5.1+git230720-4ubuntu2.3
no fix listed
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
1
linuxserver/deluge:18.04.10ac871624394
tiff@4.0.9-5ubuntu0.4
no fix listed
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
tiff@4.0.9-5ubuntu0.4
no fix listed
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
tiff@4.0.9-5ubuntu0.4
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
tiff@4.3.0-6ubuntu0.4
no fix listed
1
logiqai/flash:v3.10.265b996bc7bdc
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
louislam/uptime-kuma:2.0.24c364ef96aad
tiff@4.5.0-6+deb12u3
4.5.0-6+deb12u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.