Technology · struktur AG
struktur AG Libheif vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in struktur AG Libheif: 0 in the last 7 days and 11 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84384, was published on 18 September 2026.
- Last 7 days
- 0
- Last 90 days
- 11
- Critical, all time
- 0
- Exploited in the wild
- 0
About struktur AG Libheif
An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder.
Latest struktur AG Libheif vulnerabilities
- CVE-2026-84384: libheif decompression bomb via brotli/zlib metadatahighCVSS 7.5EPSS 0.6%
- sharp heap-based buffer overflow via libheif image parsinghighCVSS 8.9
- sharp remote code execution via malformed HEIF imagemediumCVSS 4
- Next.js and libheif RCE in HEIF/AVIF image processinginfoCVSS 9.8
- CVE-2026-48029: Strukturag libheif heap OOB read in ImageItem_Grid::decode_grid_tilehighCVSS 7.1
- CVE-2026-47709: Strukturag libheif NULL pointer dereference in heif_image_handle_get_image_tilinginfoCVSS 6.9
- CVE-2026-47254: Strukturag libheif heap buffer overflow in Track sequence handlingmediumCVSS 6.1
- CVE-2026-47251: libheif integer overflow in vvdec_push_data2infoCVSS 6.8
- CVE-2026-47247: Strukturag libheif heap information disclosure in grid image decodinghighCVSS 7.5
- CVE-2026-47178: Strukturag libheif heap out-of-bounds write in uncompressed tile decodermediumCVSS 6.1
- CVE-2026-47714: Strukturag libheif integer overflow in region.cc mask parsingmediumCVSS 6.1
- CVE-2026-49271: libheif out-of-bounds read in uncompressed HEIF decodermediumCVSS 6.5
- CVE-2026-41071: Strukturag libheif heap buffer over-read in SampleAuxInfoReaderinfoCVSS 5.1EPSS 0.0%
- CVE-2026-41069: Strukturag libheif out-of-bounds read in SampleAuxInfoReadermediumCVSS 6.5EPSS 0.0%
- CVE-2026-32882: libheif heap buffer over-read in HeifPixelImage::overlayhighCVSS 7.1
- CVE-2026-32814: Strukturag libheif uninitialized heap memory leak in grid image decodingmediumCVSS 6.5
- CVE-2026-32741: Strukturag libheif heap buffer overflow in MaskImageCodechighCVSS 7.1
- CVE-2026-32740: Strukturag libheif heap buffer overflow in grid tile compositinghighCVSS 8.8
- CVE-2026-32739: Strukturag libheif infinite loop in Box_stts::get_sample_durationmediumCVSS 6.5
- CVE-2026-32738: Strukturag libheif denial of service via integer underflow in stsc boxmediumCVSS 6.5
Most severe struktur AG Libheif vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- sharp heap-based buffer overflow via libheif image parsinghighCVSS 8.9
- CVE-2026-32740: Strukturag libheif heap buffer overflow in grid tile compositinghighCVSS 8.8
- CVE-2026-84384: libheif decompression bomb via brotli/zlib metadatahighCVSS 7.5EPSS 0.6%
- CVE-2026-47247: Strukturag libheif heap information disclosure in grid image decodinghighCVSS 7.5
- CVE-2026-48029: Strukturag libheif heap OOB read in ImageItem_Grid::decode_grid_tilehighCVSS 7.1
- CVE-2026-32882: libheif heap buffer over-read in HeifPixelImage::overlayhighCVSS 7.1
- CVE-2026-32741: Strukturag libheif heap buffer overflow in MaskImageCodechighCVSS 7.1
- CVE-2026-41069: Strukturag libheif out-of-bounds read in SampleAuxInfoReadermediumCVSS 6.5EPSS 0.0%
- CVE-2026-49271: libheif out-of-bounds read in uncompressed HEIF decodermediumCVSS 6.5
- CVE-2026-32814: Strukturag libheif uninitialized heap memory leak in grid image decodingmediumCVSS 6.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 7 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 2 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/libheif.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "struktur AG Libheif vulnerabilities", https://junglewise.ai/threats/technologies/libheif, 26 September 2026.