Количество 2
Количество 2
CVE-2026-8814
Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly compressed zTXt chunk can cause ExifReader to materialize a disproportionately large Comment value in memory.
GHSA-rr89-w3h9-m66j
ExifReader is vulnerable to denial of service via unbounded decompression of image metadata
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-8814 Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly compressed zTXt chunk can cause ExifReader to materialize a disproportionately large Comment value in memory. | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
GHSA-rr89-w3h9-m66j ExifReader is vulnerable to denial of service via unbounded decompression of image metadata | CVSS3: 5.3 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу