CVE-2026-8814

MEDIUM

Exifreader < 4.39.0 - Improper Handling of Highly Compressed Data (Data Amplification)

Title source: rule
STIX 2.1

Description

Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly compressed zTXt chunk can cause ExifReader to materialize a disproportionately large Comment value in memory.

Scores

CVSS v3 5.3
EPSS 0.0039
EPSS Percentile 30.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-409
Status published
Products (2)
None/exifreader < 4.39.0
npm/exifreader 4.20.0 - 4.39.0npm
Published May 19, 2026
Tracked Since May 19, 2026