CVE-2026-8813

This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation, causing excessive memory growth. In applications that parse attacker-supplied images, this may lead to denial of service through memory exhaustion.
Configurations

No configuration.

History

23 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) Esto afecta a las versiones del paquete exifreader anteriores a la 4.39.0. Una imagen manipulada que contiene una etiqueta ICC mluc puede establecer un recuento de registros controlado por el atacante junto con un tamaño de registro cero. Durante el análisis, ExifReader procesa repetidamente el mismo registro y añade entradas a un array sin suficiente validación de límites, causando un crecimiento excesivo de la memoria. En aplicaciones que analizan imágenes suministradas por el atacante, esto puede llevar a la denegación de servicio por agotamiento de la memoria.

19 May 2026, 14:16

Type Values Removed Values Added
References () https://security.snyk.io/vuln/SNYK-JS-EXIFREADER-16689335 - () https://security.snyk.io/vuln/SNYK-JS-EXIFREADER-16689335 -

19 May 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 07:16

Updated : 2026-07-23 20:10


NVD link : CVE-2026-8813

Mitre link : CVE-2026-8813

CVE.ORG link : CVE-2026-8813


JSON object : View

Products Affected

No product.

CWE
CWE-1284

Improper Validation of Specified Quantity in Input