Junglewise Threat Intelligence

theopolis uefi-firmware-parser heap out-of-bounds write in Tiano decompressor

Severity: critical · CVSS 9.8 · Published 2026-04-16

Technologies: Theopolis Uefi-Firmware-Parser, uefi-firmware (PyPI). Vendors: Theopolis, PyPI.

Executive brief

The uefi-firmware-parser library contains a heap out-of-bounds write vulnerability in its Tiano/EFI decompression engine. An attacker can exploit this by providing a malicious firmware image, potentially leading to arbitrary code execution or a denial-of-service crash.

Affected products

  • theopolis uefi-firmware-parser
  • PyPI uefi-firmware

Related threats