CVE-2026-34616: DNG SDK | Out-of-bounds Read (CWE-125)
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information from memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems using DNG SDK version 1.7.1 2502 or earlier are affected. Exploitation requires a victim to open a malicious file, so users or workflows that process untrusted files are the relevant exposure path.
What does an attacker need to exploit the issue?
An attacker needs to provide a malicious file and persuade or otherwise cause a victim to open it. The vulnerability has local attack-vector characteristics and does not require privileges, but it does require user interaction.
What is the likely impact if exploitation succeeds?
Successful exploitation may disclose sensitive information from memory. The provided severity vector indicates confidentiality impact without stated integrity or availability impact.