exifreader
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting exifreaderpage 1 of 1
- CVE-2026-53496MEDIUMCVSS 5.3EG 5.3fixed in 4.40.12026-07-17
ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where fin…
- CVE-2026-85715HIGHCVSS 7.5EG 7.5fixed in 4.41.12026-09-17
ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmff-iloc.js and trusts iloc itemCount and extentCount values …
- CVE-2026-8813HIGHCVSS 7.5EG 7.5fixed in 4.39.02026-05-19
This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the sam…
- CVE-2026-8814MEDIUMCVSS 5.3EG 5.3fixed in 4.39.02026-05-19
Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When …
Check whether exifreader is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for exifreader CVEs against the assets you own.
Book a Demo →