CVE-2026-49271Disclosure(struktur / libheif)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch struktur libheif systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libheif

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
libheif

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-21: 2Patch / Workaround · 2026-06-21: 1Technical Details · 2026-06-21: 206-21
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-49271 libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets usi… https://www.cve.org/CVERecord?id=CVE-2026-49271 ----- Traducción: CVE-2026-49271 lib… http://infoflow.cloud`

    Post summary

    The post references CVE‑2026‑49271 for libheif, noting a decoder issue existing before version 1.22.1, but it provides only basic vulnerability details and no PoC, exploit, or patch information.

    0000031
    88 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-49271 libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets usi… https://www.cve.org/CVERecord?id=CVE-2026-49271

    Post summary

    The CVE-2026-49271 issue involves a decoder offset validation flaw in libheif, with a patch in version 1.22.1 and no PoC or exploit code disclosed.

    00000338
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrukturlibheif---

Explore more