Out-of-bounds write in Exiv2 - #VU146329
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in Exiv2::http in http.cpp when processing a URL argument. A remote attacker can supply a specially crafted URL to cause a denial of service.
The issue can only be triggered when Exiv2 is run on a URL rather than a local file.