CVE-2026-5318Disclosure(libraw / libraw)

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-119CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libraw

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
libraw

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-02: 3Technical Details · 2026-04-02: 204-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5318 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5318 #CVE-2026-5318 #CVE #Medium #CyberSecurity #InfoSec https://t.co/figjjB73IQ

    Post summary

    The tweet announces CVE‑2026‑5318 with a medium severity rating and unspecified affected products, but provides no technical details, exploits, or patch information.

    0000029
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5318 A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG… https://www.cve.org/CVERecord?id=CVE-2026-5318

    Post summary

    The post announces a CVE discovery in LibRaw, detailing the affected function and file but provides no evidence of exploitation, PoC, or patch information.

    00000111
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5318 - LibRaw JPEG DHT losslessjpeg.cpp initval out-of-bounds write Intel Report: https://ift.tt/9VN7TzB

    Post summary

    The alert announces a new vulnerability (CVE-2026-5318) affecting LibRaw JPEG, providing basic technical details but no information on exploitation, PoC, patch, or active attacks.

    0000044
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibrawlibraw---

Explore more