SEPTEMBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-47178

MEDIUM · CVSS 6.1 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Versions 1.19.0 through 1.21.2 of libheif are vulnerable to a heap out-of-bounds write due to improper handling of crafted HEIF files, which can lead to arbitrary code execution through manipulation of the C++ vtable pointer. This vulnerability poses a medium risk, particularly for applications that utilize libheif for decoding HEIF and AVIF files. Developers and security teams using affected versions should prioritize upgrading to version 1.22.0 to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-47178
Severity
MEDIUM
CVSS
6.1
EPSS
0.20%

Original NVD Description

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)