CVE-2026-14454General(tonycoz / imager)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch tonycoz imager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-196CWE-789

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • imager

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
imager

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-09: 2Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 207-09
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    General

    Perl CPAN CVE-2026-14454: Imager before 1.033 treat unsigned EXIF IFD entry counts as signed https://www.openwall.com/lists/oss-security/2026/07/08/6 attempt to allocate a block nearly the size of the address space, which fails and kills the process. Crafted image with EXIF data could terminate a worker process.

    Post summary

    The snippet discusses CVE‑2026‑14454, noting how unsigned EXIF IFD counts are misinterpreted and can cause a crash via a large memory allocation, but it provides no PoC, exploit code, patch, or evidence of active exploitation.

    10010201
    4.6K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🖼️ Critical flaw in Imager for Perl (CVSS 9.8): CVE-2026-14454 — large EXIF IFD entry counts treated as negative numbers, enabling memory corruption via crafted images. Upgrade to v1.033 now. https://secalerts.co/vulnerability/CVE-2026-14454?utm_campaign=x https://t.co/et2rzdcOM4

    Post summary

    The tweet announces a critical memory corruption flaw in Imager for Perl, details the issue, and advises users to upgrade to version 1.033.

    00000106
    854 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptonycozimager-perl-

Explore more