๐Ÿ” CVE Alert

CVE-2026-58586

CRITICAL 9.8

Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp

CVSS Score
9.8
EPSS Score
0.4%
EPSS Percentile
28th

Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.

CWE CWE-1395
Vendor zapad
Product image::webp
Published Jul 24, 2026
Last Updated Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for zapad image::webp

Be the first to know when new critical vulnerabilities affecting zapad image::webp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ZAPAD / Image::WebP
0 < 0.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
metacpan.org: https://metacpan.org/release/ZAPAD/Image-WebP-0.2/source/webp-src/NEWS cve.org: https://www.cve.org/CVERecord?id=CVE-2023-4863 metacpan.org: https://metacpan.org/release/ZAPAD/Image-WebP-0.3.0/source/Changes