Resource exhaustion in libheif - #VU153971
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper enforcement of image size limits in libheif's pre-decode size checks when processing untrusted AVIF images. A remote attacker can submit a crafted AVIF whose in-band AV1 dimensions exceed its declared container dimensions, triggering excessive memory allocation before the image is rejected, to cause a denial of service.
The issue is confirmed with the libaom AV1 decoder backend and default security limits.