Denial-of-Service Vulnerability in libheif HEIF and AVIF File Decoder by Struktur AG
CVE-2026-32739
6.5MEDIUM
What is CVE-2026-32739?
A vulnerability in libheif versions 1.21.2 and earlier allows an attacker to craft a malicious HEIF sequence file that triggers an infinite loop during file opening. This loop consumes 100% CPU resources indefinitely, resulting in a denial-of-service condition, as the process continues to run without crashing or producing error logs. The issue occurs before any user interaction, making it particularly insidious, as it can evade crash-based monitoring solutions. The vulnerability has been addressed in version 1.22.0.
Affected Version(s)
libheif < 1.22.0
