๐Ÿ” CVE Alert

CVE-2026-3950

LOW 3.3

strukturag libheif stsz/stts track.cc load out-of-bounds

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

CWE CWE-125 CWE-119
Vendor strukturag
Product libheif
Published Mar 11, 2026
Last Updated Mar 11, 2026
Stay Ahead of the Next One

Get instant alerts for strukturag libheif

Be the first to know when new low vulnerabilities affecting strukturag libheif are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

strukturag / libheif
1.21.0 1.21.1 1.21.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.350382 vuldb.com: https://vuldb.com/?ctiid.350382 vuldb.com: https://vuldb.com/?submit.766431 github.com: https://github.com/strukturag/libheif/issues/1715 github.com: https://github.com/Niebelungen-D/pocs/tree/main/heif_dec_sequence_chunk_idx_oob github.com: https://github.com/strukturag/libheif/pull/1721 github.com: https://github.com/strukturag/libheif/

Credits

๐Ÿ” Niebelungen (VulDB User)