CVE-2026-32739
published 2026-05-19CVE-2026-32739: libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.32%
24.4th percentile
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| struktur | libheif | < 1.22.0 | 1.22.0 |
| strukturag | libheif | < 1.22.0 | 1.22.0 |
| ubuntu | libheif | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libheif vulnerabilities
vendor_ubuntu·2026-06-18·CVSS 6.5
CVE-2026-32740 [MEDIUM] libheif vulnerabilities
Title: libheif vulnerabilities
Summary: Several security issues were fixed in libheif.
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu 25.10
and Ubuntu 26.04 LTS. (CVE-2026-32738)
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files, leading to an infinite loop. An attacker
could possibly use this issue to cause libheif to use excessive
resources, resulting in a denial of service. This issue only affected
Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32739)
Elhanan Haenel discovered that libheif incorrectly handled certain
crafted HEIF/AVIF image files. An attacker could possibly use this iss
Red Hat
libheif: libheif: Denial of Service via crafted HEIF sequence file
vendor_redhat·2026-05-19·CVSS 6.5
CVE-2026-32739 [MEDIUM] CWE-835 libheif: libheif: Denial of Service via crafted HEIF sequence file
libheif: libheif: Denial of Service via crafted HEIF sequence file
A flaw was found in libheif, a HEIF and AVIF file format decoder and encoder. A remote attacker could exploit this vulnerability by providing a specially crafted HEIF (High Efficiency Image File Format) sequence file. This would trigger an infinite loop during file parsing, consuming 100% CPU indefinitely and leading to a Denial of Service (DoS) condition.
Package: glycin-loaders (Red Hat Enterprise Linux 10) - Not affected
VulDB
strukturag libheif up to 1.21.x AVIF File get_sample_duration infinite loop (GHSA-j9g7-q9hv-gq8c)
vuldb·2026-05-19·CVSS 6.5
CVE-2026-32739 [MEDIUM] strukturag libheif up to 1.21.x AVIF File get_sample_duration infinite loop (GHSA-j9g7-q9hv-gq8c)
A vulnerability marked as problematic has been reported in strukturag libheif up to 1.21.x. The affected element is the function Box_stts::get_sample_duration of the component AVIF File Handler. This manipulation causes infinite loop.
This vulnerability is handled as CVE-2026-32739. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-05-19
Published