Junglewise Threat Intelligence
CVE-2025-55304: PYSEC-2026-1355 - Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
CVE-2025-55304 · Severity: medium · CVSS 4 · Published 2026-07-07
Technologies: exiv2 (PyPI). Vendors: PyPI.
Executive brief
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Related threats
- PYSEC-2026-1354 - Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
- PYSEC-2026-1353 - Exiv2 allows Use After Free
- PYSEC-2024-107 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-servi
- PYSEC-2024-106 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds
- PYSEC-2023-233 - Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds