CVE-2026-32814Disclosure

LOWCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_error_Ok with no indication of failure, leading to an uninitialized heap memory information leak. The canvas is allocated via create_clone_image_at_new_size() → plane.alloc() → new (std::nothrow) uint8_t[allocation_size] which does not zero the memory; only the alpha plane is explicitly initialized via fill_plane(), so the Y, Cb, and Cr planes contain whatever was previously at that heap address. The failed tile's region of the canvas is never written. It retains uninitialized heap data that is delivered to the caller as decoded pixel values (4,096 bytes per Y/Cb/Cr plane = 12,288+ bytes total). Any application using libheif to decode grid-based HEIF/AVIF files with default settings is vulnerable: a crafted .heic or .avif file causes 4,096+ bytes of heap memory to appear as pixel values in the decoded image, and the calling application receives heif_error_Ok, so it has no indication the output contains heap garbage. In server-side image processing, an uploaded crafted HEIF decoded and re-encoded (e.g., as PNG/JPEG for thumbnails, CDN, social media) can leak cross-user data such as auth tokens, database results, and other users' image data. This issue has been fixed in version 1.22.0.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-908

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-19); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-19: 2Mentions · 2026-06-03: 1Active Exploitation · 2026-06-03: 1Technical Details · 2026-05-19: 1Technical Details · 2026-06-03: 105-1906-03
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Active Exploitation
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-192
Disclosure1General1
2026-06-031
Active Exploitation1
Full discourse3 posts
  • thedeepfeedai@thedeepfeed_ai
    Active Exploitation

    The threat is not theoretical. It is load-bearing. 30 MCP CVEs. An actively-exploited auth bypass (CVE-2026-32814). ~7,000 exposed MCP servers. A documented chain from one unauthenticated server to AWS credential theft. https://t.co/laDm2ikOL2

    Post summary

    The tweet reports that CVE-2026-32814, an authentication bypass, is actively exploited across roughly 7,000 MCP servers, enabling attackers to obtain AWS credentials through a documented chain.

    1000087
    14 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32814 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a … https://www.cve.org/CVERecord?id=CVE-2026-32814

    Post summary

    The text references CVE-2026-32814 for libheif, noting a problem in older versions when decoding HEIF grid images, but provides no additional technical or remedial details.

    00000115
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32814 Uninitialized Heap Memory Information Leak in libheif Versions 1.21.2 and Prior https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32814

    Post summary

    This post announces a new information‐leak vulnerability (CVE‑2026‑32814) in libheif, providing the affected versions and the nature of the flaw without any PoC or exploit details.

    0000060
    4.0K followersView on X

Explore more