CVE-2025-32024
MEDIUMBEP Imagemeta < 0.10.0 - Resource Allocation Without Limits
Title source: ruleDescription
bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The EXIF data format allows for defining excessively large data structures in relatively small payloads. Before v0.10.0, If you didn't trust the input images, this could be abused to construct denial-of-service attacks. v0.10.0 added LimitNumTags (default 5000) and LimitTagSize (default 10000) options.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/bep/imagemeta/security/advisories/GHSA-q7rw-w4cq-2j6w
Patch x_refsource_misc
https://github.com/bep/imagemeta/commit/4fd89616d8bf7f9bb892360d3fb19080ec2b4602
Scores
CVSS v4
6.9
EPSS
0.0013
EPSS Percentile
31.6%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (2)
bep/imagemeta
0 - 0.10.0Go
bep/imagemeta
< 0.10.0
Published
Apr 08, 2025
Tracked Since
Feb 18, 2026