CVE-2026-8814
MEDIUMExifreader < 4.39.0 - Improper Handling of Highly Compressed Data (Data Amplification)
Title source: ruleDescription
Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly compressed zTXt chunk can cause ExifReader to materialize a disproportionately large Comment value in memory.
Scores
CVSS v3
5.3
EPSS
0.0039
EPSS Percentile
30.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-409
Status
published
Products (2)
None/exifreader
< 4.39.0
npm/exifreader
4.20.0 - 4.39.0npm
Published
May 19, 2026
Tracked Since
May 19, 2026