VDB

CVE-2026-47178

CVE-2026-47178 PUBLISHED CVSS 6.1 MEDIUM

Reported by GitHub_M · Published July 21, 2026

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.

Risk Scores

CVSS 3.1
6.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

Affected Products

VendorProductVersions
strukturaglibheif>= 1.19.0, < 1.22.0
strukturaglibheif>= 1.19.0, < 1.22.0, >= 1.19.0, < 1.22.0

Timeline

  • May 28, 2026 CVE Published
  • Jul 22, 2026 Coalition ESS Score
  • Jul 22, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 15, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 20, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›