CVE-2023-36308

MEDIUM

Disintegration Imaging 1.6.2 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-36308. PoCs published by vtemlabs.

AI-analyzed exploit summary This repository contains functional exploit code demonstrating CVE-2023-36308, which involves a vulnerability in the imaging library's scanner functionality. The provided test cases and scanner implementation show how the vulnerability can be triggered through image processing operations.

Description

disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

Exploits (1)

nomisec WORKING POC
by vtemlabs · poc
https://github.com/vtemlabs/imaging

This repository contains functional exploit code demonstrating CVE-2023-36308, which involves a vulnerability in the imaging library's scanner functionality. The provided test cases and scanner implementation show how the vulnerability can be triggered through image processing operations.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: imaging library (vtemlabs-imaging)
No auth needed
Prerequisites: access to the imaging library · ability to process crafted images
mistral-large-3 · analyzed Jun 22, 2026 Full analysis →

Scores

CVSS v3 5.5
EPSS 0.0035
EPSS Percentile 28.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-129
Status published
Products (2)
disintegration/imaging 1.6.2
disintegration/imaging 0Go
Published Sep 05, 2023
Tracked Since Feb 18, 2026