THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pj96-35fp-cfcc (high) — ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion

[GHSA] GHSA-pj96-35fp-cfcc (high) — ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion

medgithub_advisoriesPublished 2026-09-17

GHSA-pj96-35fp-cfcc Severity: high CVE: CVE-2026-85715

ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion

## Summary ExifReader 4.41.0 is vulnerable to denial of service through a crafted HEIC or AVIF file with a malicious `iloc` box. When `offsetSize`, `lengthSize`, and `baseOffsetSize` are set to zero in the iloc header, the extent-parsing loop allocates an unbounded number of

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pj96-35fp-cfcc