cbcvebase.
CVE-2026-27631
published 2026-03-02

CVE-2026-27631: Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an…

PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.26%
16.9th percentile
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an uncaught exception was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. Due to an integer overflow, the code attempts to create a huge std::vector, which causes Exiv2 to crash with an uncaught exception. This issue has been patched in version 0.28.8.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianexiv2< exiv2 0.28.8+dfsg-1 (forky)exiv2 0.28.8+dfsg-1 (forky)
exiv2exiv2< 0.28.80.28.8
exiv2exiv2<= 0.28.8
exiv2exiv2>= 0 < 0.28.8+dfsg-10.28.8+dfsg-1
exiv2exiv2>= 0 < 0.27.5-3ubuntu1.10.27.5-3ubuntu1.1
exiv2exiv2>= 0 < 0.27.5-3ubuntu1.30.27.5-3ubuntu1.3
exiv2exiv2>= 0 < 0.27.6-1ubuntu0.10.27.6-1ubuntu0.1
exiv2exiv2>= 0 < 0.27.6-1ubuntu0.30.27.6-1ubuntu0.3
exiv2exiv2>= 0 < 0.28.5+dfsg-1ubuntu0.10.28.5+dfsg-1ubuntu0.1
exiv2exiv2>= 0 < 0.28.5+dfsg-1ubuntu0.30.28.5+dfsg-1ubuntu0.3
exiv2exiv2>= 0 < 0.25-2.1ubuntu16.04.7+esm50.25-2.1ubuntu16.04.7+esm5
exiv2exiv2>= 0 < 0.25-3.1ubuntu0.18.04.11+esm10.25-3.1ubuntu0.18.04.11+esm1
exiv2exiv2>= 0 < 0.27.2-8ubuntu2.7+esm10.27.2-8ubuntu2.7+esm1
exiv2exiv2>= 0 < 0.27.2-8ubuntu2.7+esm30.27.2-8ubuntu2.7+esm3

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv4.02.7LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.1HIGH
vendor_ubuntu8.1HIGH
vendor_debian2.7LOW
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.