StackRadar

CVE-2026-4775

High

Advisory

Published 24 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
350
of 17,787 indexed, latest versions
Container images
370
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libtiff security update

Carried by container images the latest versions of 350 of 17,787 indexed charts deploy, on 370 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+43 more4.5.0-6+deb12u4, 4.7.0-3+deb13u2348
libtiffrpm4.0.3-32.el7, 4.0.9-17.el8, 4.0.9-18.el8, 4.0.9-28.el8_8+4 more0:4.0.3-35.el7_9.2, 0:4.0.9-37.el8_10, 0:4.4.0-15.el9_7.322
OSV records
DEBIAN-CVE-2026-4775RHSA-2026:12271RHSA-2026:16055RHSA-2026:25910UBUNTU-CVE-2026-4775
Also known as
RHSA-2026:19363, RHSA-2026:19604, RHSA-2026:19659, RHSA-2026:19702

Charts affected

350 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

370 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
tiff@4.1.0+git191117-2ubuntu0.20.04.3
no fix listed
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
ghcr.io/itzg/minecraft-server:latestc1a267d9ed6d
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
libtiff@4.0.9-17.el8
0:4.0.9-37.el8_10
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
tiff@4.5.1+git230720-4ubuntu2.2
no fix listed
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
tiff@4.5.1+git230720-4ubuntu2.2
no fix listed
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
tiff@4.1.0+git191117-2ubuntu0.20.04.2
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
tiff@4.1.0+git191117-2ubuntu0.20.04.2
no fix listed
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
tiff@4.3.0-6
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
tiff@4.1.0+git191117-2ubuntu0.20.04.3
no fix listed
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
tiff@4.1.0+git191117-2ubuntu0.20.04.2
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
tiff@4.0.9-5ubuntu0.4
no fix listed
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
tiff@4.5.1+git230720-4ubuntu2.2
no fix listed
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
tiff@4.5.0-6+deb12u3
4.5.0-6+deb12u4
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
tiff@4.5.0-6+deb12u3
4.5.0-6+deb12u4
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
tiff@4.3.0-6ubuntu0.11
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
tiff@4.1.0+git191117-2ubuntu0.20.04.3
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
tiff@4.1.0+git191117-2ubuntu0.20.04.5
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
tiff@4.1.0+git191117-2ubuntu0.20.04.5
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
tiff@4.5.0-6+deb12u3
4.5.0-6+deb12u4
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
tiff@4.5.0-6
4.5.0-6+deb12u4
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
tiff@4.5.0-6
4.5.0-6+deb12u4
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.