GHSA-pj96-35fp-cfcc
HIGHCVE-2026-85715ExifReader 4.41.0 is vulnerable to denial of service through a crafted HEIC or AVIF file with a malicious iloc box. When offsetSize, lengthSize, and baseOffsetSize are set to zero in the iloc header, the extent-parsing loop allocates an unbounded number of JavaScript objects - up to itemCount × extentCount (65535 × 65535 = 4.3 billion) - without advancing the buffer offset. A 652-byte file causes
- Affected
- <= 4.41.0
- Fixed in
- 4.41.1
- Weakness
- CWE-789
- Published
- 2026-09-17
- Source
- github