CVE Database
/

CVE-2026-25884

Back to search

CVE-2026-25884

Published: Mar 2, 2026

Modified: Mar 2, 2026

PUBLISHED

Description

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.

VendorProductVersions

Exiv2

exiv2

affected
< 0.28.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now