{"id":"CVE-2020-36407","aliases":["PYSEC-2021-892"],"title":"libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.","summary":"libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","vendor":"avif","product":"avif","ecosystem":"pip","affected":["avif <= 0.8.1"],"published":"2021-07-01","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/PYSEC-2021-892","references":[{"url":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libavif/OSV-2020-1597.yaml"},{"url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24811"},{"url":"https://github.com/AOMediaCodec/libavif/commit/0a8e7244d494ae98e9756355dfbfb6697ded2ff9"}],"tags":["osv","pip"],"epss":0.01413,"epssPercentile":0.71574,"ingestedAt":"2026-07-13T18:58:05.777Z","slug":"CVE-2020-36407","body":"## Overview\n\nlibavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.\n\n## Affected packages\n\n- `avif <= 0.8.1`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}