Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-8814

4 месяца назад

Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly compressed zTXt chunk can cause ExifReader to materialize a disproportionately large Comment value in memory.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-rr89-w3h9-m66j

4 месяца назад

ExifReader is vulnerable to denial of service via unbounded decompression of image metadata

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-8814

Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly compressed zTXt chunk can cause ExifReader to materialize a disproportionately large Comment value in memory.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-rr89-w3h9-m66j

ExifReader is vulnerable to denial of service via unbounded decompression of image metadata

CVSS3: 5.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу