Libheif
48 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Libheif, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Libheif CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 3 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 2 |
| 2026-04 | 0 |
| 2026-05 | 8 |
| 2026-06 | 1 |
| 2026-07 | 7 |
| 2026-08 | 5 |
| 2026-09 | 9 |
Severity
How the 48 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High22
- Medium19
- Low5
Latest CVEs
The 15 most recently published vulnerabilities affecting Libheif.
- CVE-2026-84450libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction` (incomplete fix for CVE-2026-62289)4.3
- CVE-2026-84449libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGV3.7
- CVE-2026-84451libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an out-of-bounds read6.5
- CVE-2026-84447libheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS7.5
- CVE-2026-84384libheif: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS7.5
- CVE-2026-84444libheif uncompressed tiled image encoding allows out-of-bounds write7.4
- CVE-2026-84383libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items9.8
- CVE-2026-84446libheif: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing max_sequence_frames7.5
- CVE-2026-84448libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_region_inline_mask_data / heif_region_get_mask_image)4.0
- CVE-2026-62377libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file (context.cc:2110)4.3
- CVE-2026-62291libheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensions5.3
- CVE-2026-62292libheif: Out-of-bounds read in uncompressed unci tile range slicing—
- CVE-2026-62289libheif: Integer underflow in Fraction constructor via double clap transform application4.3
- CVE-2026-50142libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)7.5
- CVE-2026-48029libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow7.1
Product grouping is registry-driven, with AI assist and human review. How it works