CVE-2026-19082: Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags

Published Aug 7, 2026
·
Updated

Imager versions from 0.4502 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copystringtags.

copystringtags() computes an ASCII EXIF tag's length as entry->size - 1 to strip the trailing NUL. A zero-count ASCII entry sets entry->size to 0, and the derived length reaches itagsadd() as -1, which is interpreted as a request to call strlen(), scanning past the entry to the next NUL and copying those bytes into the tag. JPEG reaches this path via imdecodeexif(), as does the separate Imager::File::WEBP distribution, which is fixed by upgrading Imager.

Any caller of Imager->read() on an attacker-supplied image with such an entry may receive an exif tag holding adjacent heap bytes instead of an empty string.

Affected Software

2 affected components
Imager Imager>=0.45_02<1.034
Imager::File::WEBP>=0.45_02<1.034

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Imager to a version that resolves this vulnerability.

    Fixed in 1.034

Event History

Aug 7, 2026
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-19082?

CVE-2026-19082 has a risk rating of 26, indicating a significant vulnerability.

2

How do I fix CVE-2026-19082?

To fix CVE-2026-19082, upgrade to Imager version 1.034 or later.

3

What software is affected by CVE-2026-19082?

CVE-2026-19082 affects Imager versions from 0.45_02 up to but not including 1.034 for Perl.

4

What is the impact of CVE-2026-19082?

CVE-2026-19082 may lead to exposure of adjacent heap bytes due to an over-read in the copy_string_tags function.

5

How does CVE-2026-19082 exploit occur?

CVE-2026-19082 exploits occur via an over-read in the strlen() function caused by zero-count ASCII EXIF entries.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203