
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack https://fortbridge.co.uk/research/cve-2026-32740-nextjs-sharp-libheif-rce/
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.

CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack https://fortbridge.co.uk/research/cve-2026-32740-nextjs-sharp-libheif-rce/

CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack https://fortbridge.co.uk/research/cve-2026-32740-nextjs-sharp-libheif-rce/

We wanted to see how far CVE-2026-32740 could be pushed through a real web application. The answer was a working RCE chain through a Next.js image upload workflow. Getting a native crash was the easy part. The final proof of concept leaks the randomized libvips base through returned image pixels, turns the libheif grid overflow into a write-what-where primitive, overwrites a GOT entry, and reaches Node's in-process dynamic library loader. That gives us command execution through the application's normal upload and image optimisation routes. We ran the chain against Ubuntu and Debian native stacks. The article covers the memory layout, ASLR bypass, heap calibration, profile checks, and the GDB work behind the exploit. The proof-of-concept code is in the repository. Full write-up: https://fortbridge.co.uk/research/cve-2026-32740-nextjs-sharp-libheif-rce/ PoC repository: https://github.com/FORTBRIDGE-UK/libheif-grid-nextjs-rce #CyberSecurity #BinaryExploitation #NextJS #libheif #VulnerabilityResearch

CVE-2026-32740 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositin… https://www.cve.org/CVERecord?id=CVE-2026-32740
Post summary
CVE-2026-32740 is a heap‑buffer‑overflow vulnerability in libheif's grid tile composition for versions 1.21.2 and earlier, with no PoC, exploit, patch, or active exploitation reported.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | struktur | libheif | - | - | - |