Description
A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Restrict Use
AI Analysis

Impact

A vulnerability exists in the Get16u routine of jhead’s exif.c module, which performs an out‑of‑bounds read during EXIF parsing. The flaw allows a local user to trigger a buffer overread that can expose arbitrary data residing in memory, potentially leaking credentials or confidential information. The weakness is classified as CWE‑119 (Improper Restriction of Operations within the Bounds of a Buffer) and CWE‑125 (Out‑of‑Bounds Read).

Affected Systems

The risk applies to the Matthias‑Wandel jhead utility for EXIF parsing, versions up to and including 3.3. These versions read metadata from image files locally and are commonly invoked by users or automated scripts on the host system.

Risk and Exploitability

The CVSS score of 4.8 indicates a medium level of risk. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, implying that remote exploitation is unlikely and the risk is confined to systems where a local attacker can execute the program. Public proof‑of‑concept code is available, so an unpatched installation that processes untrusted image files could suffer data leakage or potential crashes.

Generated by OpenCVE AI on September 15, 2026 at 15:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Remove or relocate jhead from system‑wide PATH to prevent untrusted users from executing it, or run it with a restricted privilege account.
  • Wrap the jhead binary in a sandbox or container that limits its ability to read arbitrary host memory.
  • Prior to running jhead, validate or strip EXIF metadata from image files, rejecting or sanitizing fields that might trigger the Get16u routine.
  • When a patched release becomes available, upgrade jhead beyond version 3.3 to eliminate the out‑of‑bounds read.
  • If EXIF processing is not essential, disable the use of jhead entirely or replace it with a tool that performs strict bounds checking.

Generated by OpenCVE AI on September 15, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title Matthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-bounds
First Time appeared Matthias-wandel
Matthias-wandel jhead
Weaknesses CWE-119
CWE-125
CPEs cpe:2.3:a:matthias-wandel:jhead:*:*:*:*:*:*:*:*
Vendors & Products Matthias-wandel
Matthias-wandel jhead
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Matthias-wandel Jhead
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T14:58:58.979Z

Reserved: 2026-09-13T04:47:43.651Z

Link: CVE-2026-90681

cve-icon Vulnrichment

Updated: 2026-09-14T14:58:53.426Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T05:16:58.537

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read