๐Ÿ” CVE Alert

CVE-2026-32775

HIGH 7.4
CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
4th

libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.

CWE CWE-191
Vendor libexif project
Product libexif
Published Mar 16, 2026
Last Updated Apr 12, 2026
Stay Ahead of the Next One

Get instant alerts for libexif project libexif

Be the first to know when new high vulnerabilities affecting libexif project libexif are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

libexif project / libexif
0 โ‰ค 0.6.25

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/libexif/libexif/commit/7df372e9d31d7c993a22b913c813a5f7ec4f3692 github.com: https://github.com/libexif/libexif/issues/247