Assertion Failure in libheif HEIF and AVIF Decoder Affects Struktur AG
CVE-2026-62377

4.3MEDIUM

Key Information:

Vendor

Strukturag

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-62377?

The vulnerability in libheif, the HEIF and AVIF decoder developed by Struktur AG, stems from a failure in handling crafted HEIF sequences within the heif_context_read_from_memory() function. Specifically, if a crafted input leads to a complete lack of registered sequence tracks, subsequent calls to retrieve track information via the heif_context_get_track() function can lead to application crashes. In asserting builds, the API asserts that a sequence exists, causing an abort on failure. In release builds, this issue allows the dereferencing of an empty track map, resulting in undefined behavior and potential crashes. This vulnerability can be exploited through known public APIs after processing attacker-controlled input. The issue has been addressed in version 1.23.1.

Affected Version(s)

libheif < 1.23.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.