Out-of-bounds read in Exiv2 - CVE-2026-49275

 

Out-of-bounds read in Exiv2 - CVE-2026-49275

Published: August 31, 2026


Vulnerability identifier: #VU146333
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-49275
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in CrwMap::decodeBasic() when parsing crafted input. A remote attacker can supply specially crafted input to disclose sensitive information.

The issue was reproduced with the project's fuzz target, and the vendor noted that it could not be reproduced with the exiv2 command line application.


Affected software

Exiv2

How to mitigate CVE-2026-49275

Install security update from vendor's website.

Exiv2 - update to 0.28.9

External References

Related Security Bulletins