CVE-2026-32740Disclousure(struktur / libheif)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libheif

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclousure: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-09-28)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
libheif

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-19: 1Mentions · 2026-09-28: 3Technical Details · 2026-05-19: 105-1909-28
Signal classification1 categories
Disclousure
1100.0%
Referenced assets3 URLs
Full discourse4 posts
  • Nicolas Krassas@Dinosn

    CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack https://fortbridge.co.uk/research/cve-2026-32740-nextjs-sharp-libheif-rce/

    013080407.0K
    162.2K followersView on X
  • /r/netsec@_r_netsec

    CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack https://fortbridge.co.uk/research/cve-2026-32740-nextjs-sharp-libheif-rce/

    06011112.0K
    34.1K followersView on X
  • FORTBRIDGE@FORTBRIDGE

    We wanted to see how far CVE-2026-32740 could be pushed through a real web application. The answer was a working RCE chain through a Next.js image upload workflow. Getting a native crash was the easy part. The final proof of concept leaks the randomized libvips base through returned image pixels, turns the libheif grid overflow into a write-what-where primitive, overwrites a GOT entry, and reaches Node's in-process dynamic library loader. That gives us command execution through the application's normal upload and image optimisation routes. We ran the chain against Ubuntu and Debian native stacks. The article covers the memory layout, ASLR bypass, heap calibration, profile checks, and the GDB work behind the exploit. The proof-of-concept code is in the repository. Full write-up: https://fortbridge.co.uk/research/cve-2026-32740-nextjs-sharp-libheif-rce/ PoC repository: https://github.com/FORTBRIDGE-UK/libheif-grid-nextjs-rce #CyberSecurity #BinaryExploitation #NextJS #libheif #VulnerabilityResearch

    12040279
    178 followersView on X
  • CVE@CVEnew
    Disclousure

    CVE-2026-32740 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositin… https://www.cve.org/CVERecord?id=CVE-2026-32740

    Post summary

    CVE-2026-32740 is a heap‑buffer‑overflow vulnerability in libheif's grid tile composition for versions 1.21.2 and earlier, with no PoC, exploit, patch, or active exploitation reported.

    00000120
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrukturlibheif---

Explore more