<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:24:53.550992+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352466</id>
    <title>EUVD-2026-352466</title>
    <updated>2026-10-06T18:24:53.600512+00:00</updated>
    <content>EUVD-2026-352466</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352466"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8813</id>
    <title>fkie_cve-2026-8813</title>
    <updated>2026-10-06T18:24:53.600556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation, causing excessive memory growth. In applications that parse attacker-supplied images, this may lead to denial of service through memory exhaustion.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-8813"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h64w-w9pr-82m4</id>
    <title>GHSA-h64w-w9pr-82m4 — ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag</title>
    <updated>2026-10-06T18:24:53.600592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: exifreader</p>
<p>### Impact</p>
<p>When parsing an image with an embedded ICC profile that contains a crafted `multiLocalizedUnicodeType` (`mluc`) tag, ExifReader can be made to allocate memory proportional to attacker-controlled fields in the tag rather than to
the actual size of the input. Processing such an image causes excessive memory consumption and can terminate the host process (out-of-memory).</p>
<p>Any application that calls `ExifReader.load()` on untrusted images, for example, user uploads in a web service, is affected. ICC profiles are carried in JPEG, TIFF, PNG, HEIC, AVIF, JPEG XL, and WebP, so the issue is reachable from any of those formats.</p>
<p>### Patches</p>
<p>Fixed in `exifreader@4.39.0`. Upgrade with:</p>
<p>npm install exifreader@latest</p>
<p>Bower users consume the bundled `dist/` files from this repository, and the same fix is committed there.</p>
<p>### Workarounds</p>
<p>If upgrading is not immediately possible, configure a [custom build](https://github.com/mattiasw/ExifReader#configure-a-custom-build) that excludes the `icc` module so that ICC parsing (and therefore this code path) is skipped entirely.</p>
<p>### Resources</p>
<p>- Patch: https://github.com/mattiasw/ExifReader/commit/c9d88b67e127b2dcc7b46e328df468257fb2dc30</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h64w-w9pr-82m4"/>
  </entry>
</feed>
