CVE-2025-55304: Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata

Published Aug 29, 2025
·
Updated

Impact A denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted jpg image file.

Patches The bug is fixed in version v0.28.6.

References Issue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch)

For more information Please see our security policy for information about Exiv2 security.

Other sources

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted jpg image file. The bug is fixed in version 0.28.6.

MITRE

Affected Software

3 affected components
exiv2 exiv2<0.28.6
pip/Exiv2<=0.17.3
exiv2 exiv2<0.28.6

Event History

Aug 29, 2025
Advisory Published
via GitHub·02:59 PM
Data Sourced
via GitHub·02:59 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-55304?

CVE-2025-55304 is classified as a denial-of-service vulnerability.

2

What software versions are affected by CVE-2025-55304?

CVE-2025-55304 affects Exiv2 version 0.28.5 and below, including Exiv2 for pip up to and including version 0.17.3.

3

How do I fix CVE-2025-55304?

To fix CVE-2025-55304, update Exiv2 to version 0.28.6 or later.

4

What is the main issue caused by CVE-2025-55304?

CVE-2025-55304 can cause Exiv2 to run for an extended time due to a quadratic algorithm in the ICC profile parsing code.

5

What is Exiv2 used for in relation to CVE-2025-55304?

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying image metadata, which is impacted by this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203