Junglewise Threat Intelligence

CVE-2026-27281: Adobe DNG SDK integer overflow in image processing

CVE-2026-27281 · Severity: medium · CVSS 5.5 · Published 2026-03-10

Technologies: Adobe Dng Software Development Kit, Adobe DNG SDK. Vendors: Adobe.

Executive brief

Adobe's DNG SDK is a library used to process and manipulate digital image files in the DNG (Digital Negative) format. A flaw in how the library handles image dimensions could cause it to crash when processing a specially crafted image file, disrupting workflows for photographers and image editing applications that depend on the library.

Technical details

The vulnerability is an integer overflow or wraparound condition in the DNG SDK image processing logic. The flaw occurs when processing image files with malicious or unexpected dimension values, causing integer arithmetic to wrap and result in invalid memory operations or buffer overflows. Exploitation requires user interaction—an attacker must trick a user into opening a malicious DNG file through email, file sharing, or other delivery mechanisms. A successful exploit leads to denial of service (application crash or unresponsiveness). The vulnerability affects DNG SDK versions 1.7.1 build 2471 and earlier.

Affected products

  • Adobe DNG SDK 1.7.1 build 2471 and earlier

Timeline

  • 2026-03-10: disclosed: Public disclosure via NVD

References

Related threats