Description
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this vulnerability to corrupt memory, causing the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-27
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in Adobe’s DNG SDK that can corrupt memory. If successfully triggered, the application will crash or become unresponsive, effectively denying service to the user.

Affected Systems

Adobe DNG Software Development Kit versions 1.7.1 2502 and earlier are affected. Any software that incorporates these SDK releases is susceptible, including desktop and mobile applications that use DNG image processing.

Risk and Exploitability

The CVSS score of 5.5 places the issue in the medium category, and no EPSS information is available. The vulnerability requires a victim to open a crafted DNG file, so local or social‑engineering attack vectors are needed. The vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation, but the attack could still impact environments where untrusted files are processed.

Generated by OpenCVE AI on August 28, 2026 at 05:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Adobe DNG SDK to a version later than 1.7.1 2502.
  • If an upgrade is not feasible, disable or remove the DNG SDK component from the application.
  • Apply additional file validation or sandboxing around DNG file ingestion to mitigate potential exploitation until a patch is applied.

Generated by OpenCVE AI on August 28, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this vulnerability to corrupt memory, causing the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title DNG SDK | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:15:57.269Z

Reserved: 2026-03-30T17:30:36.490Z

Link: CVE-2026-34620

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:35.350

Modified: 2026-08-28T00:17:15.990

Link: CVE-2026-34620

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:00:14Z

Weaknesses