Junglewise Threat Intelligence

CVE-2026-84384: libheif decompression bomb via brotli/zlib metadata

CVE-2026-84384 · Severity: high · CVSS 7.5 · Published 2026-09-18

Technologies: struktur AG Libheif. Vendors: struktur AG.

Executive brief

libheif is a decoder and encoder for HEIF and AVIF image formats. A crafted image file with compressed metadata can cause the library to decompress data without size limits, consuming unbounded memory and crashing the application. An attacker can create a small malicious image file that triggers this denial-of-service when opened.

Technical details

The vulnerability exists in decompress_brotli() and do_inflate() functions which lack effective output-size bounds. The brotli path has no output limit, while the zlib path only checks a small temporary buffer in a code branch that valid streams do not reach. Additionally, overlapping ICEF units can decompress the same payload repeatedly, amplifying memory consumption. HeifContext::interpret_heif_file_images() processes multiple compressed metadata items during file opening, allowing an attacker-crafted file to exhaust memory during the parse phase.

Affected products

  • Struktur AG libheif 1.19.0 to 1.23.1

Timeline

  • 2026-09-18: disclosed: CVE-2026-84384 published
  • 2026-08-24: patched: Fix committed to master branch
  • 2026-08-25: patched: Version 1.23.2 released with security fix

References

Related threats