This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation, causing excessive memory growth. In applications that parse attacker-supplied images, this may lead to denial of service through memory exhaustion.
References
Configurations
No configuration.
History
19 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://security.snyk.io/vuln/SNYK-JS-EXIFREADER-16689335 - |
19 May 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-19 07:16
Updated : 2026-05-19 15:38
NVD link : CVE-2026-8813
Mitre link : CVE-2026-8813
CVE.ORG link : CVE-2026-8813
JSON object : View
Products Affected
No product.
CWE
CWE-1284
Improper Validation of Specified Quantity in Input
