Improper handling of highly compressed data in libheif - #VU145246
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in brotli and zlib decompression paths when parsing a crafted HEIF or AVIF file. A remote attacker can supply a decompression bomb to cause a denial of service.
The issue can be triggered during file open, and some variants require the uncompressed codec feature to be enabled.