VDB
CVE-2026-47178
CVE-2026-47178
PUBLISHED
CVSS 6.1 MEDIUM
Reported by GitHub_M · Published July 21, 2026
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
Risk Scores
CVSS 3.1
6.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| strukturag | libheif | >= 1.19.0, < 1.22.0 |
| strukturag | libheif | >= 1.19.0, < 1.22.0, >= 1.19.0, < 1.22.0 |
Timeline
- May 28, 2026 CVE Published
- Jul 22, 2026 Coalition ESS Score
- Jul 22, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 15, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 20, 2026 Security Advisory
References
- https://github.com/strukturag/libheif/security/advisories/GHSA-5x55-x5pf-9c6g x_refsource_CONFIRM