StackRadar

CVE-2026-4775

High

Advisory

Published 24 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
350
of 17,787 indexed, latest versions
Container images
370
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libtiff security update

Carried by container images the latest versions of 350 of 17,787 indexed charts deploy, on 370 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+43 more4.5.0-6+deb12u4, 4.7.0-3+deb13u2348
libtiffrpm4.0.3-32.el7, 4.0.9-17.el8, 4.0.9-18.el8, 4.0.9-28.el8_8+4 more0:4.0.3-35.el7_9.2, 0:4.0.9-37.el8_10, 0:4.4.0-15.el9_7.322
OSV records
DEBIAN-CVE-2026-4775RHSA-2026:12271RHSA-2026:16055RHSA-2026:25910UBUNTU-CVE-2026-4775
Also known as
RHSA-2026:19363, RHSA-2026:19604, RHSA-2026:19659, RHSA-2026:19702

Charts affected

350 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

370 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
tiff@4.5.0-6
4.5.0-6+deb12u4
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
tiff@4.1.0+git191117-2ubuntu0.20.04.3
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
libtiff@4.4.0-12.el9
0:4.4.0-15.el9_7.3
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
libtiff@4.0.9-28.el8_8
0:4.0.9-37.el8_10
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libtiff@4.0.9-18.el8
0:4.0.9-37.el8_10
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
libtiff@4.0.9-17.el8
0:4.0.9-37.el8_10
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
libtiff@4.4.0-15.el9_7.2
0:4.4.0-15.el9_7.3
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
libtiff@4.4.0-15.el9_7.2
0:4.4.0-15.el9_7.3
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
tiff@4.0.6-1ubuntu0.6
no fix listed
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
libtiff@4.4.0-12.el9
0:4.4.0-15.el9_7.3
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
libtiff@4.0.9-18.el8
0:4.0.9-37.el8_10
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
tiff@4.5.0-6
4.5.0-6+deb12u4
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.