CVE-2026-47251
CVE-2026-47251 is a medium-severity vulnerability in Struktur Libheif with a CVSS 3.x base score of 6.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-125.
Key facts
- Severity: Medium (CVSS 3.x base score 6.1)
- CVSS v4: 6.8
- EPSS exploit prediction: 0% (8th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-125
- Affected product: Struktur Libheif
- Published:
- Last modified:
Description
libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it added. The check itself can be bypassed, allowing a crafted HEIF file with a VVC track to trigger the same out-of-bounds heap read that CVE-2026-3949 was meant to prevent. This is a separate, currently-unpatched vulnerability. Issue #1712 was closed as fixed without testing the edge case where `size` is near `UINT32_MAX`. Version 1.22.0 patches the issue.
Frequently asked questions
- What is CVE-2026-47251?
- libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it added. The check itself can be bypassed, allowing a crafted HEIF file with a VVC track to trigger the same out-of-bounds heap read that CVE-2026-3949 was meant to prevent. This is a separate, currently-unpatched vulnerability. Issue #1712 was closed as fixed without testing the edge case where `size` is near `UINT32_MAX`. Version 1.22.0 patches the issue.
- How severe is CVE-2026-47251?
- CVE-2026-47251 has a CVSS 3.x base score of 6.1, rated medium severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity none, and availability high.
- Is CVE-2026-47251 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (8th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-47251?
- CVE-2026-47251 affects Struktur Libheif. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-47251?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-47251 published?
- CVE-2026-47251 was published on 2026-07-21 and last updated on 2026-07-27.
References
- https://github.com/strukturag/libheif/issues/1712
- https://github.com/strukturag/libheif/security/advisories/GHSA-p6q9-fhf2-vj9v
Affected products (1)
- cpe:2.3:a:struktur:libheif:*:*:*:*:*:*:*:*
More vulnerabilities in Struktur Libheif
- CVE-2026-32740 — High (CVSS 8.8): libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow…
- CVE-2023-49464 — High (CVSS 8.8): libheif v1.17.5 was discovered to contain a segmentation violation via the function…
- CVE-2023-49463 — High (CVSS 8.8): libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.
- CVE-2023-49462 — High (CVSS 8.8): libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc.
- CVE-2023-49460 — High (CVSS 8.8): libheif v1.17.5 was discovered to contain a segmentation violation via the function…
- CVE-2020-19499 — High (CVSS 8.8): An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of…
All CVEs affecting Struktur Libheif →
Other CWE-125 (Out-of-bounds Read) vulnerabilities
- CVE-2026-24826 — Critical (CVSS 10.0): Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read,…
- CVE-2024-22004 — Critical (CVSS 10.0): Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a…
- CVE-2021-41556 — Critical (CVSS 10.0): sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that…
- CVE-2021-21777 — Critical (CVSS 10.0): An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer…
- CVE-2017-14451 — Critical (CVSS 10.0): An exploitable out-of-bounds read vulnerability exists in libevm (Ethereum Virtual Machine) of CPP-Ethereum. A…
- CVE-2013-0767 — Critical (CVSS 10.0): The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and…