Description
TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.
Published: 2026-09-13
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via buffer over-read
Action: Apply patch
AI Analysis

Impact

TinyEXIF, a library for parsing EXIF metadata, contains a heap-based buffer over-read in the EntryParser::Fetch methods that can be triggered by a crafted SubjectArea length. This weak buffer may expose sensitive data and is classified as CWE-125, denoting unsafe read operations that can lead to information disclosure or application crashes.

Affected Systems

All builds of TinyEXIF before version 1.1.0 are affected, regardless of vendor implementation. The library is developed and maintained by cdcseacave. Any deployment that incorporates a pre‑1.1.0 release when parsing EXIF metadata from untrusted image files is vulnerable.

Risk and Exploitability

The CVSS score of 2.9 indicates a low severity, and the EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been documented. However, the over‑read can be reached through a specifically crafted SubjectArea field in EXIF metadata, which is typically embedded in image files. Therefore, the risk is modest but still relevant in environments that process untrusted images.

Generated by OpenCVE AI on September 15, 2026 at 18:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade TinyEXIF to version 1.1.0 or later.
  • Validate SubjectArea length before parsing to ensure bounds are respected.
  • If possible, disable EXIF parsing for untrusted image files or use a sandboxed environment.

Generated by OpenCVE AI on September 15, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Cdcseacave
Cdcseacave tinyexif
Vendors & Products Cdcseacave
Cdcseacave tinyexif

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Heap Buffer Over-read in TinyEXIF Leading to Information Disclosure

Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Heap Over-Read in TinyEXIF via Malformed SubjectArea Length

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Heap Over-Read in TinyEXIF via Malformed SubjectArea Length

Sun, 13 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Cdcseacave Tinyexif
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:15:29.750Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38332

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:49.047Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T21:17:01.460

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-38332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:39Z

Weaknesses