Heap Exposure Vulnerability in Imager by Tony Coz
CVE-2026-19082

7.5HIGH

Key Information:

Vendor

Tonyc

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-19082?

The Imager library versions prior to 1.034 may allow an attacker to exploit a vulnerability in the handling of ASCII EXIF entries. This occurs during the processing of image files when the function copy_string_tags incorrectly computes the length of a tag from a zero-count ASCII entry. The result can lead to unintended disclosure of adjacent heap memory bytes when an image with a specially crafted EXIF tag is processed. This vulnerability can affect any caller of Imager->read() who attempts to load images containing such entries, thereby compromising the privacy of sensitive information within adjacent memory areas.

Affected Version(s)

Imager 0.45_02 < 1.034

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arpit Jain (arpitjain099)
.