Technology · PyPI
exiv2 (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 85 vulnerabilities in exiv2 (PyPI): 0 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-55304, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 3
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest exiv2 (PyPI) vulnerabilities
- CVE-2025-55304: PYSEC-2026-1355 - Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadatamediumCVSS 4EPSS 0.2%
- CVE-2025-54080: PYSEC-2026-1354 - Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS filemediumCVSS 4EPSS 0.1%
- CVE-2025-26623: PYSEC-2026-1353 - Exiv2 allows Use After FreemediumCVSS 4EPSS 0.9%
- CVE-2024-25112: PYSEC-2024-107 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the…lowCVSS 3.1EPSS 0.2%
- CVE-2024-24826: PYSEC-2024-106 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the…lowCVSS 3.1EPSS 0.2%
- CVE-2023-44398: PYSEC-2023-233 - Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and…lowCVSS 3.1EPSS 1.0%
- CVE-2020-18831: PYSEC-2023-150 - Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote…lowCVSS 3.1EPSS 0.8%
- PYSEC-2021-884 - A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial…lowCVSS 3.1
- PYSEC-2021-882 - Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which…lowCVSS 3.1
- PYSEC-2021-883 - An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of…lowCVSS 3.1
- PYSEC-2021-885 - A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of…lowCVSS 3.1
- CVE-2020-18899: PYSEC-2021-879 - An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows…lowCVSS 3.1EPSS 1.7%
- CVE-2021-31292: PYSEC-2021-877 - An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based…lowCVSS 3.1EPSS 2.6%
- PYSEC-2021-886 - A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).lowCVSS 3.1
- PYSEC-2020-344 - In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with…lowCVSS 3.1
- PYSEC-2019-247 - Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from…lowCVSS 3.1
- PYSEC-2019-245 - Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service…lowCVSS 3.1
- PYSEC-2019-244 - Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.lowCVSS 3
- PYSEC-2019-246 - In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in…lowCVSS 3.1
- CVE-2019-13114: PYSEC-2019-257 - http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to…lowCVSS 3.1EPSS 2.1%
- PYSEC-2019-248 - An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file…lowCVSS 3
- PYSEC-2019-249 - An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file…lowCVSS 3
- CVE-2018-20099: PYSEC-2018-120 - There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A…lowCVSS 3EPSS 2.3%
- CVE-2018-20097: PYSEC-2018-118 - There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2…lowCVSS 3.1EPSS 2.3%
- CVE-2018-20096: PYSEC-2018-117 - There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2…lowCVSS 3EPSS 2.8%
Most severe exiv2 (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-26623: PYSEC-2026-1353 - Exiv2 allows Use After FreemediumCVSS 4EPSS 0.9%
- CVE-2025-55304: PYSEC-2026-1355 - Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadatamediumCVSS 4EPSS 0.2%
- CVE-2025-54080: PYSEC-2026-1354 - Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS filemediumCVSS 4EPSS 0.1%
- CVE-2021-31292: PYSEC-2021-877 - An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based…lowCVSS 3.1EPSS 2.6%
- CVE-2018-20097: PYSEC-2018-118 - There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2…lowCVSS 3.1EPSS 2.3%
- CVE-2019-13114: PYSEC-2019-257 - http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to…lowCVSS 3.1EPSS 2.1%
- CVE-2020-18899: PYSEC-2021-879 - An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows…lowCVSS 3.1EPSS 1.7%
- CVE-2023-44398: PYSEC-2023-233 - Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and…lowCVSS 3.1EPSS 1.0%
- CVE-2020-18831: PYSEC-2023-150 - Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote…lowCVSS 3.1EPSS 0.8%
- CVE-2024-24826: PYSEC-2024-106 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the…lowCVSS 3.1EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 3 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/exiv2.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "exiv2 (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/exiv2, 27 September 2026.