Description
ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmff-iloc.js and trusts iloc itemCount and extentCount values while allocating an extent object for every nested-loop iteration. When offsetSize, lengthSize, baseOffsetSize, and indexSize are zero, the extent fields consume no input bytes and the buffer offset does not advance, but the parser can still allocate up to itemCount multiplied by extentCount objects without an allocation budget. A small malicious iloc box can therefore cause hundreds of megabytes of heap growth or exhaust system memory, terminating a Node.js process and denying service to web, desktop, or mobile applications that parse untrusted images. The zero field widths are valid ISO-BMFF values indicating absent fields, so the vulnerable parser must bound work rather than relying on offset advancement. The issue is fixed in version 4.41.1.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

ExifReader parses HEIC/AVIF ISO‑BMFF files and prior to version 4.41.1 incorrectly trusts the iloc box’s itemCount and extentCount fields. A crafted image can request the parser to allocate an arbitrary number of structures without advancing the input buffer, causing hundreds of megabytes of heap expansion or complete memory exhaustion. The result is termination of the Node.js process and denial of service to any web, desktop or mobile application that loads untrusted images.

Affected Systems

The vulnerability affects the mattiasw:ExifReader JavaScript library versions earlier than 4.41.1. The parser is used in any Node.js, Electron or browser‑based application that imports ExifReader for image metadata extraction. The risk extends to all deployments that rely on ExifReader to handle HEIC or AVIF files.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity flaw with potential for remote exploitation if an attacker can supply a malicious image. Because the exploit requires only file input, any application that accepts user‑specified HEIC/AVIF files is a target. EPSS information is not available, so the exact likelihood of exploitation remains uncertain, but the lack of a bounding check means an attacker can trigger the denial of service on any affected environment. The issue is not listed in CISA's KEV catalog, but because the denial of service can disrupt availability, administrators should treat it as a high risk until a patch is applied.

Generated by OpenCVE AI on September 17, 2026 at 20:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update ExifReader to version 4.41.1 or later, which bounds iloc processing and prevents heap allocation without input consumption.
  • Ensure that the application using the library imports the patched version by checking package dependencies and rebuilding the project.
  • Restrict HEIC/AVIF image handling to trusted sources or validate image size and structure before passing it to ExifReader, and consider running the parser in a sandboxed environment with limited memory to contain any accidental overflow.

Generated by OpenCVE AI on September 17, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pj96-35fp-cfcc ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
History

Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattiasw
Mattiasw exifreader
Vendors & Products Mattiasw
Mattiasw exifreader

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmff-iloc.js and trusts iloc itemCount and extentCount values while allocating an extent object for every nested-loop iteration. When offsetSize, lengthSize, baseOffsetSize, and indexSize are zero, the extent fields consume no input bytes and the buffer offset does not advance, but the parser can still allocate up to itemCount multiplied by extentCount objects without an allocation budget. A small malicious iloc box can therefore cause hundreds of megabytes of heap growth or exhaust system memory, terminating a Node.js process and denying service to web, desktop, or mobile applications that parse untrusted images. The zero field widths are valid ISO-BMFF values indicating absent fields, so the vulnerable parser must bound work rather than relying on offset advancement. The issue is fixed in version 4.41.1.
Title ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
Weaknesses CWE-789
CWE-835
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Mattiasw Exifreader
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:54:27.224Z

Reserved: 2026-09-04T14:45:10.647Z

Link: CVE-2026-85715

cve-icon Vulnrichment

Updated: 2026-09-17T15:54:23.091Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:18:15.790

Modified: 2026-09-30T17:51:36.337

Link: CVE-2026-85715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')