Junglewise Threat Intelligence

CVE-2026-84447: libheif reference amplification denial of service

CVE-2026-84447 · Severity: high · CVSS 7.5 · Published 2026-09-18

Technologies: Strukturag Libheif. Vendors: Strukturag.

Executive brief

libheif is a decoder and encoder for HEIF and AVIF image formats used in image processing and media applications. In versions 1.23.1 and earlier, specially crafted image files with nested reference chains (grid, iovl, and iden structures) can cause excessive CPU and memory usage, allowing an attacker to trigger a denial of service by making the application hang or crash when processing a malicious file.

Technical details

The vulnerability is a resource amplification bug in derived-image reference handling where the cycle-detection set (processed_ids) is passed by value per branch, causing the same base image to be decoded repeatedly along different paths through the reference graph. An attacker can construct deeply nested or widely branching reference structures that exponentially multiply decode operations and memory consumption, bypassing decode caching and operation budgets. The fix (v1.23.2) introduces a shared per-traversal decode operation budget, depth guards, and memoization to bound the exponential blow-up.

Affected products

  • strukturag libheif 1.23.1 and earlier

Timeline

  • 2026-08-25: patched: Fix released in libheif v1.23.2
  • 2026-09-18: disclosed: CVE-2026-84447 and GHSA-x8xm-cm2c-cfc8 published

References

Related threats