CVE-2026-27596

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. The out-of-bounds read is at a 4GB offset, which usually causes Exiv2 to crash. This issue has been patched in version 0.28.8.
Configurations

Configuration 1 (hide)

cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:27

Type Values Removed Values Added
Summary
  • (es) Exiv2 es una librería de C++ y una utilidad de línea de comandos para leer, escribir, eliminar y modificar metadatos de imagen Exif, IPTC, XMP e ICC. Antes de la versión 0.28.8, se encontró una lectura fuera de límites en Exiv2. La vulnerabilidad está en el componente de vista previa, que solo se activa al ejecutar Exiv2 con un argumento adicional de línea de comandos, como -pp. La lectura fuera de límites está en un desplazamiento de 4 GB, lo que generalmente provoca que Exiv2 falle. Este problema ha sido parcheado en la versión 0.28.8.

05 Mar 2026, 22:16

Type Values Removed Values Added
References () https://github.com/Exiv2/exiv2/commit/eaa9e21aabe06b3f91cfe66686f5ebc3ca3c0ed4 - () https://github.com/Exiv2/exiv2/commit/eaa9e21aabe06b3f91cfe66686f5ebc3ca3c0ed4 - Patch
References () https://github.com/Exiv2/exiv2/issues/3511 - () https://github.com/Exiv2/exiv2/issues/3511 - Issue Tracking
References () https://github.com/Exiv2/exiv2/pull/3512 - () https://github.com/Exiv2/exiv2/pull/3512 - Issue Tracking
References () https://github.com/Exiv2/exiv2/security/advisories/GHSA-3wgv-fg4w-75x7 - () https://github.com/Exiv2/exiv2/security/advisories/GHSA-3wgv-fg4w-75x7 - Patch, Vendor Advisory
CPE cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:*
First Time Exiv2 exiv2
Exiv2
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

02 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 20:16

Updated : 2026-06-17 10:27


NVD link : CVE-2026-27596

Mitre link : CVE-2026-27596

CVE.ORG link : CVE-2026-27596


JSON object : View

Products Affected

exiv2

  • exiv2
CWE
CWE-125

Out-of-bounds Read

CWE-191

Integer Underflow (Wrap or Wraparound)