{"id":"CVE-2026-38332","title":"TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.","summary":"TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.","severity":"low","cvss":2.9,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-125"],"vendor":"cdcseacave","product":"TinyEXIF","affected":["TinyEXIF < 1.1.0"],"published":"2026-09-13","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:00:03.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-38332","references":[{"url":"https://github.com/cdcseacave/TinyEXIF/issues/24","label":"cve@mitre.org"},{"url":"https://github.com/cdcseacave/TinyEXIF/pull/25","label":"cve@mitre.org"},{"url":"https://github.com/cdcseacave/TinyEXIF/security/advisories/GHSA-jqj2-8c2j-gx82","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.00116,"epssPercentile":0.01847,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T14:56:47.881372Z"},"ingestedAt":"2026-09-14T15:23:07.468Z","slug":"CVE-2026-38332","body":"## Overview\n\nTinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":16,"depthScoreParts":{"impact":16,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}