Report: Update: CVE-2026-8813 - Apache ExifReader ICC mluc Tag Buffer Overflow Vulnerability

Report: Update: CVE-2026-8813 - Apache ExifReader ICC mluc Tag Buffer Overflow Vulnerability

CVE ID :CVE-2026-8813 Published : May 19, 2026, 7:16 a.m. | 30 minutes ago Description :This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation, causing excessive memory growth. In applications that parse attacker-supplied images, this may lead to denial of service through memory exhaustion. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
May 19, 2026
Impact: denial of service