Integer Overflow Vulnerability in libheif HEIF and AVIF Decoder by Struktur AG
CVE-2026-47251

6.8MEDIUM

Key Information:

Vendor

Strukturag

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-47251?

A vulnerability exists in the libheif library, an encoder and decoder for HEIF and AVIF file formats, due to an integer overflow introduced after a previous fix. The improperly implemented security check allows attackers to craft malicious HEIF files that can bypass checks and trigger an out-of-bounds heap read. This defect arises from insufficient testing of edge cases, specifically when the size parameter approaches UINT32_MAX. As a result, this issue remains unpatched and poses a risk to users running versions below 1.22.0.

Affected Version(s)

libheif < 1.22.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.