OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-102504

HIGH · CVSS 7.5 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Imager versions prior to 1.037 for Perl are vulnerable to a denial-of-service condition when processing raw images with an out-of-range raw_datachannels value, leading to an unhandled exit of the process. This vulnerability arises from the lack of range-checking, which can result in excessive memory allocation requests and subsequent process termination. Developers and organizations utilizing Imager for image processing should prioritize addressing this issue to prevent potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102504
Severity
HIGH
CVSS
7.5
EPSS
0.39%

Original NVD Description

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.