Description
A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Heap-based buffer overflow leading to local memory corruption
Action: Assess Impact
AI Analysis

Impact

The reported flaw is a heap-based buffer overflow in the ProcessGpsInfo routine of the WebP EXIF handler component. By tampering with the TAG_GPS_LAT and TAG_GPS_LONG arguments supplied in an image’s EXIF GPS segment, an attacker can corrupt memory on a local host, potentially causing a crash or arbitrary memory overwrite. The vulnerability is classified as CWE‑119 and CWE‑122, indicating an unbounded buffer write on the heap.

Affected Systems

The issue appears in the popular jhead utility provided by Matthias‑Wandel. Versions up to and including 3.3 are affected. No specific revision number is given beyond the 3.3 cutoff, and the project has yet to release a fix. Users running the tool for local image metadata extraction or analysis are therefore exposed to the risk.

Risk and Exploitability

The CVSS score of 4.8 places this vulnerability in the moderate range, and its exploitability is limited to local access. The EPSS score is < 1%, indicating a low probability of exploitation, and the entry is not listed in the CISA KEV catalog, which suggests that wide‑scale exploitation has not been documented. Nevertheless, any local actor capable of injecting crafted EXIF data can trigger the overflow, potentially destabilising the process that performs the metadata read. Because the problem is not remotely exploitable, the overall impact is constrained to environments where the library processes untrusted files.

Generated by OpenCVE AI on September 15, 2026 at 15:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest jhead release that addresses the heap overflow, if one is available.
  • If an upgrade is not feasible, run the jhead utility inside a sandboxed or container‑based environment to contain any memory corruption.
  • Continuously monitor system and application logs for crashes or abnormal memory behaviour when processing images that contain EXIF GPS metadata.

Generated by OpenCVE AI on September 15, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title Matthias-Wandel jhead WebP EXIF gpsinfo.c ProcessGpsInfo heap-based overflow
First Time appeared Matthias-wandel
Matthias-wandel jhead
Weaknesses CWE-119
CWE-122
CPEs cpe:2.3:a:matthias-wandel:jhead:*:*:*:*:*:*:*:*
Vendors & Products Matthias-wandel
Matthias-wandel jhead
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Matthias-wandel Jhead
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:58:11.023Z

Reserved: 2026-09-13T04:47:53.206Z

Link: CVE-2026-90682

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:16.336Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T05:16:58.730

Modified: 2026-09-15T14:17:27.287

Link: CVE-2026-90682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-122

    Heap-based Buffer Overflow