StackRadar

CVE-2026-4775

High

Advisory

Published 24 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
351
of 17,781 indexed, latest versions
Container images
371
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libtiff security update

Carried by container images the latest versions of 351 of 17,781 indexed charts deploy, on 371 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+43 more4.5.0-6+deb12u4, 4.7.0-3+deb13u2349
libtiffrpm4.0.3-32.el7, 4.0.9-17.el8, 4.0.9-18.el8, 4.0.9-28.el8_8+4 more0:4.0.3-35.el7_9.2, 0:4.0.9-37.el8_10, 0:4.4.0-15.el9_7.322
OSV records
DEBIAN-CVE-2026-4775RHSA-2026:12271RHSA-2026:16055RHSA-2026:25910UBUNTU-CVE-2026-4775
Also known as
RHSA-2026:19363, RHSA-2026:19604, RHSA-2026:19659, RHSA-2026:19702

Charts affected

351 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-4775.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tiff@4.3.0-6ubuntu0.13
no fix listed

Open the chart page →

7,849

Container images carrying it

371 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
tiff@4.1.0+git191117-2ubuntu0.20.04.12
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
teknas09/bird-pod:latest12a1fa85c4aa
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
tiff@4.0.6-1ubuntu0.2
no fix listed
1
theradius/loggia:0.463ba348546ec
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
thongngo3301/stakefish:latesta341af5976e3
tiff@4.5.0-6
4.5.0-6+deb12u4
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
tiff@4.3.0-6ubuntu0.4
no fix listed
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
tiff@4.3.0-6ubuntu0.3
no fix listed
1
timescale/timescaledb-ha:pg16d7db8f1085a3
tiff@4.3.0-6ubuntu0.13
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
tiff@4.3.0-6ubuntu0.10
no fix listed
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
tiff@4.3.0-6
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
tiff@4.0.6-1ubuntu0.2
no fix listed
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
trueosiris/vrising:latest9356f98ad561
tiff@4.3.0-6ubuntu0.13
no fix listed
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
tiff@4.3.0-6ubuntu0.7
no fix listed
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
tiff@4.0.9-5ubuntu0.9
no fix listed
1
vlebediantsev/notes-admin-front:latest007c6670ff48
tiff@4.5.0-6
4.5.0-6+deb12u4
1
vlebediantsev/notes-project-front:latest945675fd2636
tiff@4.5.0-6
4.5.0-6+deb12u4
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
tiff@4.5.0-6
4.5.0-6+deb12u4
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
tiff@4.3.0-6ubuntu0.9
no fix listed
1
xeladock/mysql_dns:latest4baf531453f1
tiff@4.3.0-6
no fix listed
1
xeladock/nginx2:latestc259a67b1dff
tiff@4.3.0-6
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
tiff@4.5.1+git230720-4ubuntu2.2
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
tiff@4.1.0+git191117-2ubuntu0.20.04.2
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
tiff@4.5.1+git230720-4ubuntu2.4
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
tiff@4.3.0-6
no fix listed
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
tiff@4.5.1+git230720-4ubuntu2.4
no fix listed
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
tiff@4.3.0-6
no fix listed
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tiff@4.3.0-6ubuntu0.13
no fix listed
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
tiff@4.7.0-3ubuntu5
no fix listed
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
tiff@4.5.1+git230720-4ubuntu2.4
no fix listed
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
tiff@4.3.0-6ubuntu0.7
no fix listed
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.