CVE-2026-3707Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in MrNanko webp4j up to 1.3.x. The affected element is the function DecodeGifFromMemory of the file src/main/c/gif_decoder.c. Such manipulation of the argument canvas_height leads to integer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The name of the patch is 89771b201c66d15d29e4cc016d8aae82b6a5fbe1. It is advisable to implement a patch to correct this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-189CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-08: 2Technical Details · 2026-03-08: 103-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3707 A vulnerability was identified in MrNanko webp4j up to 1.3.x. The affected element is the function DecodeGifFromMemory of the file src/main/c/gif_decoder.c. Such manipu… https://www.cve.org/CVERecord?id=CVE-2026-3707

    Post summary

    A CVE-2026-3707 vulnerability affecting the DecodeGifFromMemory function in MrNanko webp4j has been identified, but no PoC, exploit code, active exploitation, patch, or detailed technical info is provided.

    00000102
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3707 Integer Overflow in MrNanko webp4j DecodeGifFromMemory Function via Canvas Height https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3707

    Post summary

    A new vulnerability (CVE-2026-3707) involving an integer overflow in webp4j's DecodeGifFromMemory function was disclosed, with no evidence of active exploitation, PoC, or patch at this time.

    0000038
    4.0K followersView on X

Explore more