CVE-2026-38332: Low severity TinyEXIF vulnerability
Published Sep 13, 2026
·Updated
TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.
Affected Software
1 affected component
TinyEXIF<1.1.0
Event History
Sep 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
TinyEXIF versions before 1.1.0 are affected. The issue is in EntryParser::Fetch methods when processing a crafted SubjectArea length.
2
What access does an attacker need to exploit this?
The CVSS vector indicates local attack access and high attack complexity, with no privileges or user interaction required. Exploitation requires reaching the affected parsing code with a crafted SubjectArea length.
3
What is the expected impact?
The reported flaw is a heap-based buffer over-read. The CVSS vector reports no confidentiality or integrity impact and low availability impact.