Junglewise Threat Intelligence

CVE-2026-8814: ExifReader data amplification in PNG zTXt metadata decompression

CVE-2026-8814 · Severity: medium · CVSS 5.3 · Published 2026-05-19

Technologies: Mattiasw ExifReader. Vendors: Mattias Wadstein.

Executive brief

ExifReader, a library used to read metadata from image files, is vulnerable to a denial-of-service attack. An attacker can provide a specially crafted image that, when processed, consumes excessive amounts of memory and CPU power. This can cause the application to slow down significantly or crash, potentially disrupting services that process user-uploaded images.

Technical details

ExifReader (versions 4.20.0 to 4.38.1) contains a data amplification vulnerability (CWE-409) in its asynchronous decompression utility. When processing images via the asynchronous API (e.g., ExifReader.load), the library fails to bound the size of decompressed metadata blocks such as PNG zTXt/iCCP chunks or JPEG XL Brotli-compressed blocks. An attacker can exploit this by providing a small image file with highly compressed metadata that expands significantly upon decompression (e.g., 1000x expansion), leading to heap exhaustion and CPU spikes. The issue is fixed in version 4.39.0 by implementing incremental reading and a configurable decompression limit (defaulting to 128 MiB).

Affected products

  • mattiasw ExifReader >= 4.20.0, < 4.39.0

Timeline

  • 2026-05-18: disclosed: Initial disclosure by reporter
  • 2026-05-19: advisory: NVD publication date
  • 2026-05-29: patched: GitHub Advisory reviewed and updated with patch information

References

Related threats