Allocation of Resources Without Limits or Throttling in libheif - #VU147372
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper enforcement of resource limits in the Emscripten item-ID helper functions when processing a crafted HEIF file with an excessive number of items. A remote attacker can submit a specially crafted HEIF file to cause a denial of service.
The issue affects non-standalone Emscripten builds, where an item count controls a stack allocation that can leave the WebAssembly instance unusable.