CVE-2026-8813
HIGHexifreader < 4.39.0 - Denial of Service via ICC mluc Tag Parsing
Title source: llmDescription
This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation, causing excessive memory growth. In applications that parse attacker-supplied images, this may lead to denial of service through memory exhaustion.
Scores
CVSS v3
7.5
EPSS
0.0046
EPSS Percentile
36.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1284
Status
published
Products (2)
None/exifreader
< 4.39.0
npm/exifreader
2.10.0 - 4.39.0npm
Published
May 19, 2026
Tracked Since
May 19, 2026