5.3
MEDIUM CVSS 3.1
CVE-2026-62291
libheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensions
Description

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 auxiliary alpha plane can cause attacker-controlled heap corruption during a normal decode and re-encode workflow. Track_Visual::decode_next_image_sample() calls transfer_channel_from_image_as() without checking that the auxiliary alpha dimensions match the main frame. The resulting inconsistent image reaches heif_track_decode_next_image() and then heif_context_encode_image(). In unc_encoder::encode(), unc_encoder_component_interleave::encode_tile() sizes its buffer with compute_tile_data_size_bytes() using the primary dimensions but copies each component using its actual plane dimensions. The oversized alpha plane is therefore copied beyond the allocation, causing an out-of-bounds write; the inverse size mismatch can also produce an out-of-bounds read. This issue is fixed in version 1.23.1.

INFO

Published Date :

Aug. 18, 2026, 10:17 p.m.

Last Modified :

Aug. 18, 2026, 10:17 p.m.

Remotely Exploit :

No
Affected Products

The following products are affected by CVE-2026-62291 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 MEDIUM [email protected]
CVSS 3.1 MEDIUM MITRE-CVE
Solution
Update libheif to version 1.23.1 or later to fix heap corruption.
  • Update libheif to version 1.23.1.
  • Apply patches for affected versions.
  • Rebuild applications using libheif.
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-62291.

URL Resource
https://github.com/strukturag/libheif/commit/ac5521ad50399885de96bb6a0733a5d2442740f9
https://github.com/strukturag/libheif/releases/tag/v1.23.1
https://github.com/strukturag/libheif/security/advisories/GHSA-xpw3-9rhw-482x
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-62291 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-62291 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-62291 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-62291 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by [email protected]

    Aug. 18, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'strukturag', 'product': 'libheif', 'versions': [{'status': 'affected', 'version': '< 1.23.1'}]}]
    Added Description libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 auxiliary alpha plane can cause attacker-controlled heap corruption during a normal decode and re-encode workflow. Track_Visual::decode_next_image_sample() calls transfer_channel_from_image_as() without checking that the auxiliary alpha dimensions match the main frame. The resulting inconsistent image reaches heif_track_decode_next_image() and then heif_context_encode_image(). In unc_encoder::encode(), unc_encoder_component_interleave::encode_tile() sizes its buffer with compute_tile_data_size_bytes() using the primary dimensions but copies each component using its actual plane dimensions. The oversized alpha plane is therefore copied beyond the allocation, causing an out-of-bounds write; the inverse size mismatch can also produce an out-of-bounds read. This issue is fixed in version 1.23.1.
    Added CVSS V3.1 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
    Added CWE CWE-125
    Added CWE CWE-787
    Added Reference https://github.com/strukturag/libheif/commit/ac5521ad50399885de96bb6a0733a5d2442740f9
    Added Reference https://github.com/strukturag/libheif/releases/tag/v1.23.1
    Added Reference https://github.com/strukturag/libheif/security/advisories/GHSA-xpw3-9rhw-482x
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.