Vendor
struktur AG vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in struktur AG: 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-48029, was published on 22 July 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 0
- Exploited in the wild
- 0
About struktur AG
A German software company specializing in open-source multimedia and communication solutions.
struktur AG technologies
Latest struktur AG vulnerabilities
- CVE-2026-48029: Strukturag libheif heap OOB read in ImageItem_Grid::decode_grid_tilehighCVSS 7.1
- CVE-2026-47709: Strukturag libheif NULL pointer dereference in heif_image_handle_get_image_tilinginfoCVSS 6.9
- CVE-2026-47254: Strukturag libheif heap buffer overflow in Track sequence handlingmediumCVSS 6.1
- CVE-2026-47251: libheif integer overflow in vvdec_push_data2infoCVSS 6.8
- CVE-2026-47247: Strukturag libheif heap information disclosure in grid image decodinghighCVSS 7.5
- CVE-2026-47178: Strukturag libheif heap out-of-bounds write in uncompressed tile decodermediumCVSS 6.1
- CVE-2026-47714: Strukturag libheif integer overflow in region.cc mask parsingmediumCVSS 6.1
- CVE-2026-45383: Strukturag libde265 heap buffer overflow in decode_slice_unit_WPPinfoCVSS 6.9
- CVE-2026-45382: strukturag libde265 out-of-bounds read in decode_slice_unit_tilesinfoCVSS 6.9
- CVE-2026-49346: Strukturag libde265 heap buffer overflow in de265_image_get_bufferhighCVSS 7.1
- CVE-2026-49337: Strukturag libde265 unbounded heap growth in read_slice_NALmediumCVSS 4.3
- CVE-2026-49295: Strukturag libde265 out-of-bounds write in process_reference_picture_sethighCVSS 7.1
- CVE-2026-49271: libheif out-of-bounds read in uncompressed HEIF decodermediumCVSS 6.5
- CVE-2026-41071: Strukturag libheif heap buffer over-read in SampleAuxInfoReaderinfoCVSS 5.1EPSS 0.0%
- CVE-2026-41069: Strukturag libheif out-of-bounds read in SampleAuxInfoReadermediumCVSS 6.5EPSS 0.0%
- CVE-2026-32882: libheif heap buffer over-read in HeifPixelImage::overlayhighCVSS 7.1
- CVE-2026-32814: Strukturag libheif uninitialized heap memory leak in grid image decodingmediumCVSS 6.5
- CVE-2026-32741: Strukturag libheif heap buffer overflow in MaskImageCodechighCVSS 7.1
- CVE-2026-32740: Strukturag libheif heap buffer overflow in grid tile compositinghighCVSS 8.8
- CVE-2026-32739: Strukturag libheif infinite loop in Box_stts::get_sample_durationmediumCVSS 6.5
- CVE-2026-32738: Strukturag libheif denial of service via integer underflow in stsc boxmediumCVSS 6.5
Most severe struktur AG vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-32740: Strukturag libheif heap buffer overflow in grid tile compositinghighCVSS 8.8
- CVE-2026-47247: Strukturag libheif heap information disclosure in grid image decodinghighCVSS 7.5
- CVE-2026-48029: Strukturag libheif heap OOB read in ImageItem_Grid::decode_grid_tilehighCVSS 7.1
- CVE-2026-49346: Strukturag libde265 heap buffer overflow in de265_image_get_bufferhighCVSS 7.1
- CVE-2026-49295: Strukturag libde265 out-of-bounds write in process_reference_picture_sethighCVSS 7.1
- CVE-2026-32882: libheif heap buffer over-read in HeifPixelImage::overlayhighCVSS 7.1
- CVE-2026-32741: Strukturag libheif heap buffer overflow in MaskImageCodechighCVSS 7.1
- CVE-2026-41069: Strukturag libheif out-of-bounds read in SampleAuxInfoReadermediumCVSS 6.5EPSS 0.0%
- CVE-2026-49271: libheif out-of-bounds read in uncompressed HEIF decodermediumCVSS 6.5
- CVE-2026-32814: Strukturag libheif uninitialized heap memory leak in grid image decodingmediumCVSS 6.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 9 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/struktur-ag.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "struktur AG vulnerabilities", https://junglewise.ai/threats/vendors/struktur-ag, 26 September 2026.