Denial-of-Service Vulnerability in libheif HEIF and AVIF File Decoder by Struktur AG
CVE-2026-32739

6.5MEDIUM

Key Information:

Vendor

Strukturag

Status
Vendor
CVE Published:
19 May 2026

What is CVE-2026-32739?

A vulnerability in libheif versions 1.21.2 and earlier allows an attacker to craft a malicious HEIF sequence file that triggers an infinite loop during file opening. This loop consumes 100% CPU resources indefinitely, resulting in a denial-of-service condition, as the process continues to run without crashing or producing error logs. The issue occurs before any user interaction, making it particularly insidious, as it can evade crash-based monitoring solutions. The vulnerability has been addressed in version 1.22.0.

Affected Version(s)

libheif < 1.22.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.