Out-of-bounds read in Exiv2 - CVE-2026-49275
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in CrwMap::decodeBasic() when parsing crafted input. A remote attacker can supply specially crafted input to disclose sensitive information.
The issue was reproduced with the project's fuzz target, and the vendor noted that it could not be reproduced with the exiv2 command line application.