Open Source Security mailing list@oss_securityPatch
The message announces that version 0.28.8 of Exiv2 provides patches for three CVEs involving out-of-bounds reads and an integer overflow, offering a direct mitigation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new out‑of‑bounds read vulnerability (CVE‑2026‑25884) affecting Exiv2 CRW image parser versions before 0.28.8 has been disclosed, with no PoC, exploit, or patch details provided.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE-2026-25884, an out-of-bounds vulnerability in Exiv2 before version 0.28.8, and links to the official CVE record.
CVE@CVEnewGeneral
The text references CVE-2026-25884, noting an out-of-bounds issue in Exiv2 before version 0.28.8, but provides no further details such as PoC, exploit, patch, or active exploitation.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
A new CVE-2026-25884 affecting Exiv2 has been reported, describing an out-of-bounds read in CrwMap::decode0x0805, with an Intel report linked for further details.