CVE-2026-58586
Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.
| CWE | CWE-1395 |
| Vendor | zapad |
| Product | image::webp |
| Published | Jul 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for zapad image::webp
Be the first to know when new unknown vulnerabilities affecting zapad image::webp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ZAPAD / Image::WebP
0 โค 0.2