Vulnerability Details CVE-2026-20911
A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.6%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-20911
-
cpe:2.3:a:libraw:libraw:0.22.0
-
cpe:2.3:a:libraw:libraw:0.22.1