SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-50142

HIGH · CVSS 7.5 EPSS 0.56% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects libheif, a library used for decoding and encoding HEIF and AVIF file formats, specifically versions 1.19.0 to 1.23.0. An attacker can exploit this flaw by crafting a specific HEIF sequence that leads to unbounded heap allocation, potentially causing significant memory exhaustion, crashes, or stalls in applications utilizing this library. Organizations using affected versions of libheif should prioritize updating to version 1.23.0 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-50142
Severity
HIGH
CVSS
7.5
EPSS
0.56%

Original NVD Description

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_boxes.cc, Box_stsz::parse() applies max_sequence_frames only to variable-size samples, so fixed-size mode accepts an attacker-controlled sample_count without a bound. In libheif/sequences/track.cc, Track::load() also adds current_sample_idx and samples_per_chunk in 32-bit arithmetic, allowing the consistency check to be bypassed by wraparound. The resulting values reach the Chunk::Chunk() allocation path, which can consume gigabytes of memory and crash or stall the process through memory exhaustion. This issue is fixed in version 1.23.0.