{"schema_version":1,"title":"exiv2 (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 85 vulnerabilities in exiv2 (PyPI): 0 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-55304, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/exiv2","json_url":"https://junglewise.ai/threats/technologies/exiv2.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/exiv2","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":85,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":3,"last_365_days":3},"latest":[{"cve":"CVE-2025-55304","cvss":4,"epss":0.0024,"slug":"cve-2025-55304-exiv2-has-quadratic-performance-in-icc-profile-parsing-in","title":"PYSEC-2026-1355 - Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:02.626933+00:00","url":"https://junglewise.ai/threats/cve-2025-55304-exiv2-has-quadratic-performance-in-icc-profile-parsing-in"},{"cve":"CVE-2025-54080","cvss":4,"epss":0.0014,"slug":"cve-2025-54080-exiv2-segmentation-faults-in-exiv2-epsimage-writemetadata-via","title":"PYSEC-2026-1354 - Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:02.528413+00:00","url":"https://junglewise.ai/threats/cve-2025-54080-exiv2-segmentation-faults-in-exiv2-epsimage-writemetadata-via"},{"cve":"CVE-2025-26623","cvss":4,"epss":0.0092,"slug":"cve-2025-26623-exiv2-use-after-free-in-tiffsubifd","title":"PYSEC-2026-1353 - Exiv2 allows Use After Free","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:50.15571+00:00","url":"https://junglewise.ai/threats/cve-2025-26623-exiv2-use-after-free-in-tiffsubifd"},{"cve":"CVE-2024-25112","cvss":3.1,"epss":0.0022,"slug":"cve-2024-25112-exiv2-has-a-denial-of-service-due-to-unbounded-recursion-in","title":"PYSEC-2024-107 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-servi","severity":"low","exploited":false,"published_at":"2024-02-12T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-25112-exiv2-has-a-denial-of-service-due-to-unbounded-recursion-in"},{"cve":"CVE-2024-24826","cvss":3.1,"epss":0.0024,"slug":"cve-2024-24826-exiv2-has-an-out-of-bounds-read-in-quicktimevideo","title":"PYSEC-2024-106 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds","severity":"low","exploited":false,"published_at":"2024-02-12T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-24826-exiv2-has-an-out-of-bounds-read-in-quicktimevideo"},{"cve":"CVE-2023-44398","cvss":3.1,"epss":0.0097,"slug":"cve-2023-44398-pysec-2023-233-exiv2-is-a-c-library-and-a-command-line-utility-to","title":"PYSEC-2023-233 - Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds","severity":"low","exploited":false,"published_at":"2023-11-06T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-44398-pysec-2023-233-exiv2-is-a-c-library-and-a-command-line-utility-to"},{"cve":"CVE-2020-18831","cvss":3.1,"epss":0.008,"slug":"cve-2020-18831-pysec-2023-150-buffer-overflow-vulnerability-in-texttodatabuf","title":"PYSEC-2023-150 - Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service","severity":"low","exploited":false,"published_at":"2023-08-22T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-18831-pysec-2023-150-buffer-overflow-vulnerability-in-texttodatabuf"},{"cvss":3.1,"slug":"pysec-2021-884-a-float-point-exception-in-the-printlong-function-in-4731c646","title":"PYSEC-2021-884 - A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via","severity":"low","exploited":false,"published_at":"2021-08-23T22:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2021-884-a-float-point-exception-in-the-printlong-function-in-4731c646"},{"cvss":3.1,"slug":"pysec-2021-882-exiv2-0-27-99-0-has-a-global-buffer-over-read-in-exiv2-61a4ddf8","title":"PYSEC-2021-882 - Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an inf","severity":"low","exploited":false,"published_at":"2021-08-23T22:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2021-882-exiv2-0-27-99-0-has-a-global-buffer-over-read-in-exiv2-61a4ddf8"},{"cvss":3.1,"slug":"pysec-2021-883-an-invalid-memory-access-in-the-decode-function-in-iptc-86380c28","title":"PYSEC-2021-883 - An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a cra","severity":"low","exploited":false,"published_at":"2021-08-23T22:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2021-883-an-invalid-memory-access-in-the-decode-function-in-iptc-86380c28"},{"cvss":3.1,"slug":"pysec-2021-885-a-stack-exhaustion-issue-in-the-printifdstructure-34dc9979","title":"PYSEC-2021-885 - A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a cr","severity":"low","exploited":false,"published_at":"2021-08-19T22:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2021-885-a-stack-exhaustion-issue-in-the-printifdstructure-34dc9979"},{"cve":"CVE-2020-18899","cvss":3.1,"epss":0.0166,"slug":"cve-2020-18899-pysec-2021-879-an-uncontrolled-memory-allocation-in-databufdata","title":"PYSEC-2021-879 - An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of ser","severity":"low","exploited":false,"published_at":"2021-08-19T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-18899-pysec-2021-879-an-uncontrolled-memory-allocation-in-databufdata"},{"cve":"CVE-2021-31292","cvss":3.1,"epss":0.0256,"slug":"cve-2021-31292-pysec-2021-877-an-integer-overflow-in-crwmap-encode0x1810-of","title":"PYSEC-2021-877 - An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of s","severity":"low","exploited":false,"published_at":"2021-07-26T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-31292-pysec-2021-877-an-integer-overflow-in-crwmap-encode0x1810-of"},{"cvss":3.1,"slug":"pysec-2021-886-a-buffer-overflow-vulnerability-in-the-databuf-function-6e475317","title":"PYSEC-2021-886 - A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).","severity":"low","exploited":false,"published_at":"2021-07-13T22:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2021-886-a-buffer-overflow-vulnerability-in-the-databuf-function-6e475317"},{"cvss":3.1,"slug":"pysec-2020-344-in-jp2image-readmetadata-in-jp2image-cpp-in-exiv2-0-27-2-26b3aa30","title":"PYSEC-2020-344 - In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumptio","severity":"low","exploited":false,"published_at":"2020-01-27T05:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2020-344-in-jp2image-readmetadata-in-jp2image-cpp-in-exiv2-0-27-2-26b3aa30"},{"cvss":3.1,"slug":"pysec-2019-247-exiv2-0-27-2-allows-attackers-to-trigger-a-crash-in-c42f4172","title":"PYSEC-2019-247 - Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirect","severity":"low","exploited":false,"published_at":"2019-10-09T19:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-247-exiv2-0-27-2-allows-attackers-to-trigger-a-crash-in-c42f4172"},{"cvss":3.1,"slug":"pysec-2019-245-exiv2-pngimage-readmetadata-in-pngimage-cpp-in-exiv2-0-299e4881","title":"PYSEC-2019-245 - Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-rea","severity":"low","exploited":false,"published_at":"2019-07-28T19:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-245-exiv2-pngimage-readmetadata-in-pngimage-cpp-in-exiv2-0-299e4881"},{"cvss":3,"slug":"pysec-2019-244-exiv2-0-27-99-0-has-a-heap-based-buffer-over-read-in-11c6027f","title":"PYSEC-2019-244 - Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.","severity":"low","exploited":false,"published_at":"2019-07-28T19:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-244-exiv2-0-27-99-0-has-a-heap-based-buffer-over-read-in-11c6027f"},{"cvss":3.1,"slug":"pysec-2019-246-in-exiv2-0-27-99-0-there-is-an-out-of-bounds-read-in-8afb03f4","title":"PYSEC-2019-246 - In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.","severity":"low","exploited":false,"published_at":"2019-07-28T19:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-246-in-exiv2-0-27-99-0-there-is-an-out-of-bounds-read-in-8afb03f4"},{"cve":"CVE-2019-13114","cvss":3.1,"epss":0.0213,"slug":"cve-2019-13114-pysec-2019-257-http-c-in-exiv2-through-0-27-1-allows-a-malicious","title":"PYSEC-2019-257 - http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by retu","severity":"low","exploited":false,"published_at":"2019-06-30T23:15:10.267+00:00","url":"https://junglewise.ai/threats/cve-2019-13114-pysec-2019-257-http-c-in-exiv2-through-0-27-1-allows-a-malicious"},{"cvss":3,"slug":"pysec-2019-248-an-issue-was-discovered-in-exiv2-0-27-there-is-infinite-514934ba","title":"PYSEC-2019-248 - An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be tr","severity":"low","exploited":false,"published_at":"2019-02-25T15:29:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-248-an-issue-was-discovered-in-exiv2-0-27-there-is-infinite-514934ba"},{"cvss":3,"slug":"pysec-2019-249-an-issue-was-discovered-in-exiv2-0-27-there-is-infinite-bec001f7","title":"PYSEC-2019-249 - An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cpp. This can be trigg","severity":"low","exploited":false,"published_at":"2019-02-25T15:29:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-249-an-issue-was-discovered-in-exiv2-0-27-there-is-infinite-bec001f7"},{"cve":"CVE-2018-20099","cvss":3,"epss":0.0229,"slug":"cve-2018-20099-pysec-2018-120-there-is-an-infinite-loop-in-exiv2-jp2image","title":"PYSEC-2018-120 - There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denia","severity":"low","exploited":false,"published_at":"2018-12-12T10:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-20099-pysec-2018-120-there-is-an-infinite-loop-in-exiv2-jp2image"},{"cve":"CVE-2018-20097","cvss":3.1,"epss":0.0229,"slug":"cve-2018-20097-pysec-2018-118-there-is-a-segv-in-exiv2-internal-tiffparserworker","title":"PYSEC-2018-118 - There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to","severity":"low","exploited":false,"published_at":"2018-12-12T10:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-20097-pysec-2018-118-there-is-a-segv-in-exiv2-internal-tiffparserworker"},{"cve":"CVE-2018-20096","cvss":3,"epss":0.0276,"slug":"cve-2018-20096-pysec-2018-117-there-is-a-heap-based-buffer-over-read-in-the","title":"PYSEC-2018-117 - There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to","severity":"low","exploited":false,"published_at":"2018-12-12T10:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-20096-pysec-2018-117-there-is-a-heap-based-buffer-over-read-in-the"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":78,"url":"https://junglewise.ai/threats/technologies/picklescan"}],"technology":{"hub":true,"name":"exiv2 (PyPI)","slug":"exiv2","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/exiv2"},"most_severe":[{"cve":"CVE-2025-26623","cvss":4,"epss":0.0092,"slug":"cve-2025-26623-exiv2-use-after-free-in-tiffsubifd","title":"PYSEC-2026-1353 - Exiv2 allows Use After Free","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:50.15571+00:00","url":"https://junglewise.ai/threats/cve-2025-26623-exiv2-use-after-free-in-tiffsubifd"},{"cve":"CVE-2025-55304","cvss":4,"epss":0.0024,"slug":"cve-2025-55304-exiv2-has-quadratic-performance-in-icc-profile-parsing-in","title":"PYSEC-2026-1355 - Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:02.626933+00:00","url":"https://junglewise.ai/threats/cve-2025-55304-exiv2-has-quadratic-performance-in-icc-profile-parsing-in"},{"cve":"CVE-2025-54080","cvss":4,"epss":0.0014,"slug":"cve-2025-54080-exiv2-segmentation-faults-in-exiv2-epsimage-writemetadata-via","title":"PYSEC-2026-1354 - Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:02.528413+00:00","url":"https://junglewise.ai/threats/cve-2025-54080-exiv2-segmentation-faults-in-exiv2-epsimage-writemetadata-via"},{"cve":"CVE-2021-31292","cvss":3.1,"epss":0.0256,"slug":"cve-2021-31292-pysec-2021-877-an-integer-overflow-in-crwmap-encode0x1810-of","title":"PYSEC-2021-877 - An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of s","severity":"low","exploited":false,"published_at":"2021-07-26T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-31292-pysec-2021-877-an-integer-overflow-in-crwmap-encode0x1810-of"},{"cve":"CVE-2018-20097","cvss":3.1,"epss":0.0229,"slug":"cve-2018-20097-pysec-2018-118-there-is-a-segv-in-exiv2-internal-tiffparserworker","title":"PYSEC-2018-118 - There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to","severity":"low","exploited":false,"published_at":"2018-12-12T10:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-20097-pysec-2018-118-there-is-a-segv-in-exiv2-internal-tiffparserworker"},{"cve":"CVE-2019-13114","cvss":3.1,"epss":0.0213,"slug":"cve-2019-13114-pysec-2019-257-http-c-in-exiv2-through-0-27-1-allows-a-malicious","title":"PYSEC-2019-257 - http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by retu","severity":"low","exploited":false,"published_at":"2019-06-30T23:15:10.267+00:00","url":"https://junglewise.ai/threats/cve-2019-13114-pysec-2019-257-http-c-in-exiv2-through-0-27-1-allows-a-malicious"},{"cve":"CVE-2020-18899","cvss":3.1,"epss":0.0166,"slug":"cve-2020-18899-pysec-2021-879-an-uncontrolled-memory-allocation-in-databufdata","title":"PYSEC-2021-879 - An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of ser","severity":"low","exploited":false,"published_at":"2021-08-19T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-18899-pysec-2021-879-an-uncontrolled-memory-allocation-in-databufdata"},{"cve":"CVE-2023-44398","cvss":3.1,"epss":0.0097,"slug":"cve-2023-44398-pysec-2023-233-exiv2-is-a-c-library-and-a-command-line-utility-to","title":"PYSEC-2023-233 - Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds","severity":"low","exploited":false,"published_at":"2023-11-06T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-44398-pysec-2023-233-exiv2-is-a-c-library-and-a-command-line-utility-to"},{"cve":"CVE-2020-18831","cvss":3.1,"epss":0.008,"slug":"cve-2020-18831-pysec-2023-150-buffer-overflow-vulnerability-in-texttodatabuf","title":"PYSEC-2023-150 - Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service","severity":"low","exploited":false,"published_at":"2023-08-22T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-18831-pysec-2023-150-buffer-overflow-vulnerability-in-texttodatabuf"},{"cve":"CVE-2024-24826","cvss":3.1,"epss":0.0024,"slug":"cve-2024-24826-exiv2-has-an-out-of-bounds-read-in-quicktimevideo","title":"PYSEC-2024-106 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds","severity":"low","exploited":false,"published_at":"2024-02-12T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-24826-exiv2-has-an-out-of-bounds-read-in-quicktimevideo"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}