CVE-2026-27281: DNG SDK | Integer Overflow or Wraparound (CWE-190)
DNG SDK versions 1.7.1 2471 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27281?
CVE-2026-27281 is a critical severity vulnerability that can lead to application denial-of-service.
How do I fix CVE-2026-27281?
To fix CVE-2026-27281, upgrade to a version of the DNG SDK later than 1.7.1 2471.
What types of systems are affected by CVE-2026-27281?
CVE-2026-27281 affects DNG SDK versions 1.7.1 2471 and earlier.
What can an attacker do with CVE-2026-27281?
An attacker can exploit CVE-2026-27281 to crash the application or make it unresponsive.
Is there a workaround for CVE-2026-27281 while waiting for a patch?
There are no officially recommended workarounds for CVE-2026-27281; upgrading is the best course of action.