Description
ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where findMetaBox() and parseBox() accept an eight-byte box header without confirming that fields required by the parsed box remain in the DataView. A valid ftyp box followed by an empty free or unknown box can cause an unchecked full-box version read, while a truncated extended-size box can make getBoxLength() and hasEmptyHighBits() read absent size fields. The resulting RangeError escapes the main parsing path and can abort an application request or worker when parse errors are not defensively caught, causing denial of service. This issue is fixed in version 4.40.1.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

ExifReader is a JavaScript library that parses EXIF metadata. In versions preceding 4.40.1, the load functions can forward HEIC or AVIF data to the ISO‑BMFF parser in src\/image-header-iso-bmff.js, where findMetaBox() and parseBox() accept an eight‑byte box header without verifying that the required fields remain in the DataView. This flaw allows an attacker to supply crafted box structures, such as a valid ftyp box followed by an empty free or unknown box, which can trigger an unchecked full‑box version read, or a truncated extended‑size box that causes getBoxLength() and hasEmptyHighBits() to read absent size fields. The resulting RangeError propagates out of the parsing routine and can abort an application request or worker if the error is not defensively caught, leading to a denial‑of‑service condition. The issue is resolved in ExifReader version 4.40.1.

Affected Systems

The vulnerability affects the ExifReader library from the vendor mattiasw, impacting all releases prior to version 4.40.1. Any project that loads EXIF data via ExifReader.load() or its asynchronous file and URL loaders when processing HEIC or AVIF images is potentially exposed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % shows extremely low probability of targeted exploitation, and the flaw is not listed in CISA’s KEV catalogue. Attackers would need to supply a specially crafted HEIC or AVIF file containing malformed boxes to trigger the error. The likely vector is a web application or client‑side code that loads user‑supplied images via ExifReader.load() or its asynchronous loaders. If the application does not catch the resulting RangeError, the exception can terminate the request or worker, causing a temporary loss of service for the affected user or session.

Generated by OpenCVE AI on September 21, 2026 at 00:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update ExifReader to version 4.40.1 or later to apply the vendor‑supplied fix
  • Wrap calls to ExifReader.load() and the associated asynchronous loaders in try/catch blocks so that unhandled RangeErrors are caught and handled gracefully
  • If the library cannot be upgraded, validate or sanitize input before passing it to ExifReader, or disable support for these formats until a secure version is available

Generated by OpenCVE AI on September 21, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g77h-45rf-hcx4 ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes
History

Tue, 15 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattiasw
Mattiasw exifreader
Vendors & Products Mattiasw
Mattiasw exifreader

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where findMetaBox() and parseBox() accept an eight-byte box header without confirming that fields required by the parsed box remain in the DataView. A valid ftyp box followed by an empty free or unknown box can cause an unchecked full-box version read, while a truncated extended-size box can make getBoxLength() and hasEmptyHighBits() read absent size fields. The resulting RangeError escapes the main parsing path and can abort an application request or worker when parse errors are not defensively caught, causing denial of service. This issue is fixed in version 4.40.1.
Title ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes
Weaknesses CWE-248
CWE-755
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Mattiasw Exifreader
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:52:04.154Z

Reserved: 2026-06-09T17:05:25.059Z

Link: CVE-2026-53496

cve-icon Vulnrichment

Updated: 2026-09-14T18:51:19.202Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T17:17:46.213

Modified: 2026-09-30T19:38:27.293

Link: CVE-2026-53496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-248

    Uncaught Exception

  • CWE-755

    Improper Handling of Exceptional Conditions