CVE-2026-27631
MEDIUMexiv2 < 0.28.8 - Denial of Service via Preview Command Line Argument
Title source: llmDescription
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an uncaught exception was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. Due to an integer overflow, the code attempts to create a huge std::vector, which causes Exiv2 to crash with an uncaught exception. This issue has been patched in version 0.28.8.
References (4)
Core 4
Core References
Issue Tracking x_refsource_misc
https://github.com/Exiv2/exiv2/pull/3514
Vendor Advisory x_refsource_confirm
https://github.com/Exiv2/exiv2/security/advisories/GHSA-p2pw-7935-c73j
Issue Tracking x_refsource_misc
https://github.com/Exiv2/exiv2/issues/3513
Patch x_refsource_misc
https://github.com/Exiv2/exiv2/commit/659db316eef745899a778a1e0b760a971d1b69df
Scores
CVSS v3
5.3
EPSS
0.0026
EPSS Percentile
16.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-248
Status
published
Products (1)
exiv2/exiv2
< 0.28.8
Published
Mar 02, 2026
Tracked Since
Mar 03, 2026