Vulnerability Details CVE-2026-21413
A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.5%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-21413
-
cpe:2.3:a:libraw:libraw:0.22.0
-
cpe:2.3:a:libraw:libraw:0.22.1