StackRadar

CVE-2026-4775

High

Advisory

Published 24 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
351
of 17,781 indexed, latest versions
Container images
371
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libtiff security update

Carried by container images the latest versions of 351 of 17,781 indexed charts deploy, on 371 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+43 more4.5.0-6+deb12u4, 4.7.0-3+deb13u2349
libtiffrpm4.0.3-32.el7, 4.0.9-17.el8, 4.0.9-18.el8, 4.0.9-28.el8_8+4 more0:4.0.3-35.el7_9.2, 0:4.0.9-37.el8_10, 0:4.4.0-15.el9_7.322
OSV records
DEBIAN-CVE-2026-4775RHSA-2026:12271RHSA-2026:16055RHSA-2026:25910UBUNTU-CVE-2026-4775
Also known as
RHSA-2026:19363, RHSA-2026:19604, RHSA-2026:19659, RHSA-2026:19702

Charts affected

351 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-4775.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tiff@4.3.0-6ubuntu0.13
no fix listed

Open the chart page →

7,849

Container images carrying it

371 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
tiff@4.0.6-1ubuntu0.4
no fix listed
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
tiff@4.0.6-1ubuntu0.6
no fix listed
4
library/nginx:1.27.1287ff321f9e3
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
4
ciscolabs/rtsp-client:latesta7b60ec88285
tiff@4.1.0+git191117-2ubuntu0.20.04.5
no fix listed
3
ciscolabs/rtsp-server:latestb59fc10bb821
tiff@4.1.0+git191117-2ubuntu0.20.04.5
no fix listed
3
library/nginx:1.25:1.25.5a484819eb602
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
tiff@4.0.6-1ubuntu0.5
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
tiff@4.5.0-6
4.5.0-6+deb12u4
3
quay.io/devtron/ai-agent:0.0.16545dac92173
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tiff@4.5.0-6+deb12u3
4.5.0-6+deb12u4
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
tiff@4.5.1+git230720-4ubuntu2
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
tiff@4.5.0-6
4.5.0-6+deb12u4
2
homebridge/homebridge:latest77c685a40911
tiff@4.5.1+git230720-4ubuntu2.5
no fix listed
2
kurento/kurento-media-server:latest03c0d34d0828
tiff@4.5.1+git230720-4ubuntu2.4
no fix listed
2
library/nginx:1.27.098f8ec75657d
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
2
library/nginx:1.29.49dd288848f44
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
2
library/python:3.7eedf63967cdb
tiff@4.5.0-6
4.5.0-6+deb12u4
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
tiff@4.7.0-3+deb13u1
4.7.0-3+deb13u2
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
tiff@4.5.0-6
4.5.0-6+deb12u4
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
tiff@4.5.0-6
4.5.0-6+deb12u4
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
2
opendatacube/ows:latest668cbb41473c
tiff@4.5.1+git230720-4ubuntu2.2
no fix listed
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
tiff@4.5.1+git230720-4ubuntu2.2
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
tiff@4.3.0-6ubuntu0.1
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
tiff@4.5.0-6+deb12u3
4.5.0-6+deb12u4
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
tiff@4.5.0-6+deb12u3
4.5.0-6+deb12u4
2
5200710/hadoop:3.2.3-java8092d3088a5fb
tiff@4.1.0+git191117-2ubuntu0.20.04.11
no fix listed
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
tiff@4.1.0+git191117-2ubuntu0.20.04.1
no fix listed
1
akaunting/akaunting:3.0.1552811b36ec3a
tiff@4.5.0-6
4.5.0-6+deb12u4
1
allegroai/clearml:2.0.0-613713ae38f7daf
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
tiff@4.3.0-6ubuntu0.10
no fix listed
1
anujdatar/cups:25.07.01685df04a643b
tiff@4.5.0-6+deb12u2
4.5.0-6+deb12u4
1
apache/tika:latest-full80072bb73dd3
tiff@4.7.0-3ubuntu5
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u4
1
assistiot/open_api_backend:1.1.230812ba93555
tiff@4.3.0-6ubuntu0.7
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
tiff@4.5.0-6
4.5.0-6+deb12u4
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
tiff@4.1.0+git191117-2ubuntu0.20.04.12
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
tiff@4.5.0-6
4.5.0-6+deb12u4
1
avzini/web-app:latestf40b30210ed0
tiff@4.5.0-6
4.5.0-6+deb12u4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.