A high-severity denial-of-service vulnerability affecting exifreader versions tested, identified as CVE-2026-85715 with a CVSS score of 7.5, affects ExifReader versions prior to 4.41.0. The flaw occurs due to insufficient validation of size fields in the iloc header when parsing crafted HEIC or AVIF files, allowing attackers to create an excessive number of extent objects without advancing the buffer offset. This results in memory exhaustion and a crash of the Node.js process, leading to significant business impact due to potential system crashes and data loss. The vulnerability can be exploited via crafted files with a malicious iloc box, specifically HEIC and AVIF formats. A suggested fix involves adding a maximum per-item extent limit or skipping the inner loop when all extent field sizes are zero in the getItems function of.
We recommend you to update ExifReader to version 4.41.1.[/subscribe_to_unlock_form]
A high-severity denial-of-service vulnerability affecting exifreader versions tested, identified as CVE-2026-85715 with a CVSS score of 7.5, affects ExifReader versions prior to 4.41.0. The flaw occurs due to insufficient validation of size fields in the iloc header when parsing crafted HEIC or AVIF files, allowing attackers to create an excessive number of extent objects without advancing the buffer offset. This results in memory exhaustion and a crash of the Node.js process, leading to significant business impact due to potential system crashes and data loss. The vulnerability can be exploited via crafted files with a malicious iloc box, specifically HEIC and AVIF formats. A suggested fix involves adding a maximum per-item extent limit or skipping the inner loop when all extent field sizes are zero in the getItems function of.
We recommend you to update ExifReader to version 4.41.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]