CVE-2026-13708Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. i_readjpeg_wiol walks the marker list libjpeg returns and, for each APP13 marker, allocates a new buffer with *iptc_itext = mymalloc(...) and overwrites the previous pointer without freeing it. Only the final payload is later turned into a Perl scalar and freed, so a JPEG with N such markers leaks the first N-1 payloads on every read. In a long-lived process, such as an upload or thumbnailing service, repeated reads accumulate these leaks and exhaust available memory, a denial of service. The same handler ships bundled in the Imager distribution, where versions before 1.032 are affected and the fix ships in 1.032.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-13705: Imager before 1.032 has a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle https://www.openwall.com/lists/oss-security/2026/07/06/3 CVE-2026-13708: Imager::File::JPEG before 1.003 may leak heap memory https://www.openwall.com/lists/oss-security/2026/07/06/4

    Post summary

    Two new CVEs (CVE‑2026‑13705 and CVE‑2026‑13708) for the Perl CPAN Imager library are disclosed, detailing heap memory vulnerabilities without mention of exploits, patches, or false positives.

    10000137
    4.7K followersView on X

Explore more