CVE-2025-55304

MEDIUM

Exiv2 < 0.28.6 - Denial of Service via Crafted JPEG ICC Profile

Title source: llm
STIX 2.1

Description

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted jpg image file. The bug is fixed in version 0.28.6.

References (4)

Core 4
Core References
Exploit, Issue Tracking x_refsource_misc
https://github.com/Exiv2/exiv2/issues/3333

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-407
Status published
Products (2)
exiv2/exiv2 < 0.28.6
pypi/Exiv2 0PyPI
Published Aug 29, 2025
Tracked Since Feb 18, 2026