Improper handling of highly compressed data in libheif - #VU145246

 

Improper handling of highly compressed data in libheif - #VU145246

Published: August 25, 2026


Vulnerability identifier: #VU145246
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-409
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in brotli and zlib decompression paths when parsing a crafted HEIF or AVIF file. A remote attacker can supply a decompression bomb to cause a denial of service.

The issue can be triggered during file open, and some variants require the uncompressed codec feature to be enabled.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.2

External References

Related Security Bulletins