CVE-2026-25884HIGH 8.1EPSS p22.1%

CVE-2026-25884CVE-2026-25884

Description

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
EPSS0.31% probability of exploitation · percentile 22.1% · 2026-06-18T12:00:27Z
Published2026-03-02
Last modified2026-03-05

Underlying weaknesses· 1

CWE-125

References

  1. https://github.com/Exiv2/exiv2/commit/cbba4d206512fe63e12d164fdd1881562f072a9d
  2. https://github.com/Exiv2/exiv2/pull/3462
  3. https://github.com/Exiv2/exiv2/security/advisories/GHSA-9mxq-4j5g-5wrp

1

TypeTargetConfidenceTier
WeaknessOut-of-bounds Readcwe-1250%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-26623
CVE
ExifTool Remote Code Execution Vulnerability
CVE
CVE-2026-28693
CVE
CVE-2026-45358
CVE
CVE-2026-25897
CVE
CVE-2026-26284
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.