๐Ÿ” CVE Alert

CVE-2026-47251

UNKNOWN 0.0

libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_data2

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it added. The check itself can be bypassed, allowing a crafted HEIF file with a VVC track to trigger the same out-of-bounds heap read that CVE-2026-3949 was meant to prevent. This is a separate, currently-unpatched vulnerability. Issue #1712 was closed as fixed without testing the edge case where `size` is near `UINT32_MAX`. Version 1.22.0 patches the issue.

CWE CWE-125 CWE-190
Vendor strukturag
Product libheif
Published Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for strukturag libheif

Be the first to know when new unknown vulnerabilities affecting strukturag libheif are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

strukturag / libheif
< 1.22.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/strukturag/libheif/security/advisories/GHSA-p6q9-fhf2-vj9v github.com: https://github.com/strukturag/libheif/issues/1712