Image::WebP Vulnerability in Perl Affects Multiple Versions of libwebp
CVE-2026-58586
Currently unrated
What is CVE-2026-58586?
The Image::WebP module for Perl incorporates a problematic version of libwebp, specifically version 0.3.0, which was released in 2013. This version contains multiple known security flaws, including the vulnerability identified as CVE-2023-4863. Due to this flawed integration, any application that processes untrusted WebP images through the Image::WebP module is at risk, as it utilizes the outdated and vulnerable decoder bundled within the module. Notably, even if the system libwebp is updated, the vulnerabilities persist due to reliance on the embedded library.
Affected Version(s)
Image::WebP 0 <= 0.2
