Image::WebP Vulnerability in Perl Affects Multiple Versions of libwebp
CVE-2026-58586

Currently unrated

Key Information:

Vendor

Zapad

Vendor
CVE Published:
24 July 2026

What is CVE-2026-58586?

The Image::WebP module for Perl incorporates a problematic version of libwebp, specifically version 0.3.0, which was released in 2013. This version contains multiple known security flaws, including the vulnerability identified as CVE-2023-4863. Due to this flawed integration, any application that processes untrusted WebP images through the Image::WebP module is at risk, as it utilizes the outdated and vulnerable decoder bundled within the module. Notably, even if the system libwebp is updated, the vulnerabilities persist due to reliance on the embedded library.

Affected Version(s)

Image::WebP 0 <= 0.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.