Libheif
This hub aggregates every CVE we track for Libheif, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
38
CVEs tracked
0
Critical
18
High
0
In CISA KEV
Severity distribution
HIGH18MEDIUM16LOW4
Monthly trend
1
0
0
0
0
0
3
0
0
0
0
0
0
0
1
0
0
2
0
8
1
7
4
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Libheif.
- CVE-2026-62377libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file (context.cc:2110)4.3
- CVE-2026-62291libheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensions5.3
- CVE-2026-62289libheif: Integer underflow in Fraction constructor via double clap transform application4.3
- CVE-2026-50142libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)7.5
- CVE-2026-48029libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow7.1
- CVE-2026-47709libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispe5.5
- CVE-2026-47254libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vector Access6.1
- CVE-2026-47251libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_data26.1
- CVE-2026-47247libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation7.5
- CVE-2026-47178libheif has Heap Out Of Bounds Write in unci subsystem6.1
- CVE-2026-47714libheif has integer overflow in inline mask size calculation that causes undersized buffer allocation6.1
- CVE-2026-49271libheif: Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoder6.5
- CVE-2026-41071libheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence file with mismatched saiz sample count8.1
- CVE-2026-41069libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)6.5
- CVE-2026-32882libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride7.1
Product normalization is registry-driven with AI assist and human review. How it works