Junglewise Threat Intelligence

CVE-2026-3031: TOKUHIROM Image::EPEG use of unmaintained Epeg library

CVE-2026-3031 · Severity: info · CVSS 0 · Published 2026-07-16

Executive brief

The Image::EPEG Perl module, which is used for fast JPEG thumbnail generation, includes an outdated and unsupported version of the Epeg library from 2004. Using unmaintained software components increases the risk that unpatched security flaws could be exploited to disrupt services or compromise systems processing images. Organizations using this module should evaluate the risks of relying on code that has not received security updates in over two decades.

Technical details

Image::EPEG (up to version 0.15) bundles Epeg 0.9.0, a C library for JPEG thumbnailing that has been unmaintained since 2004. This is classified as CWE-1104: Use of Unmaintained Third Party Components. While no specific exploit is detailed in the advisory, the use of ancient image processing code poses a significant risk of memory corruption vulnerabilities (such as buffer overflows or heap spray attacks) common in legacy C-based media libraries. The vulnerability is inherent in the distribution of the Perl module. There are currently no known patches that update the underlying library to a modern, supported version.

Affected products

  • TOKUHIROM Image::EPEG 0 through 0.15

Timeline

  • 2026-07-16: disclosed: CVE published by CPANSec via NVD

References