SecAlerts
l

libheif

Security Risk Profile

39
/100
low

Security Risk Score

Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 5, 2024 to present

19
Total CVEs
8
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
39/100
low
📈 3 in Last 30 Days

Severity Distribution

Critical
0
High
8
Medium
11
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
Null Pointer Dereference
3
2
Infoleak
2
3
Buffer Overflow
2
4
Integer Underflow
1

Most Affected Products

1. libheif libheif21
2. debian/libheif12
3. struktur Libheif10

Recent Vulnerabilities

See more →
CVE-2026-84451
CVSS 6.5medium

libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an out-of-bounds read

Sep 18, 2026🔧 No Patch
CVE-2026-84447
CVSS 7.5high

libheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS

Sep 18, 2026🔧 No Patch
CVE-2026-84448
CVSS 4.0medium

libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_region_inline_mask_data / heif_region_get_mask_image)

Sep 18, 2026🔧 No Patch
CVE-2026-62377
CVSS 4.3medium

libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file (context.cc:2110)

Aug 18, 2026
CVE-2026-62292
CVSS 8.7high

libheif: Out-of-bounds read in uncompressed unci tile range slicing

Aug 18, 2026
CVE-2026-62289
CVSS 4.3medium

libheif: Integer underflow in Fraction constructor via double clap transform application

Aug 18, 2026
CVE-2026-47247
CVSS 7.5high

libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation

Jul 21, 2026🔧 No Patch
CVE-2026-49271
CVSS 6.5medium

libheif: Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoder

Jun 19, 2026
CVE-2026-41071
CVSS 5.1medium

libheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence file with mismatched saiz sample count

May 22, 2026
CVE-2026-41069
CVSS 6.5medium

libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)

May 22, 2026

Monitor libheif in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.