CVE-2023-4863High· 8.8▾ Abyssal⚠ Exploited in the wild0dayPoC availablelibwebp: OOB write in BuildHuffmanTable
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 20 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Federal remediation due Oct 4, 2023
100%
100% → 100%
14 GitHub repos
Last analysed / modified upstream
Added to the CISA catalog on Sep 13, 2023. Federal remediation due Oct 4, 2023. View catalog ↗
Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.
libwebp-sys2 < 0.1.8libwebp-sys < 0.9.3electron >= 22.0.0, < 22.3.24electron >= 24.0.0, < 24.8.3electron >= 25.0.0, < 25.8.1electron >= 26.0.0, < 26.2.1electron >= 27.0.0-beta.1, < 27.0.0-beta.2SkiaSharp >= 2.0.0, < 2.88.6github.com/chai2010/webp >= 1.1.2, < 1.4.0pillow < 10.0.1webp < 0.2.6magick.net-q16-anycpu < 13.3.0magick.net-q16-hdri-anycpu < 13.3.0magick.net-q16-x64 < 13.3.0magick.net-q8-anycpu < 13.3.0magick.net-q8-openmp-x64 < 13.3.0magick.net-q8-x64 < 13.3.0github.com/chai2010/webp < 0.0.0-20250406010349-76805d5a8860github.com/chai2010/webp >= 0.0.0, < 1.1.2-0.20250406010349-76805d5a8860Upgrade to a patched release:
libwebp-sys2 0.1.8libwebp-sys 0.9.3electron 22.3.24electron 24.8.3electron 25.8.1electron 26.2.1electron 27.0.0-beta.2SkiaSharp 2.88.6github.com/chai2010/webp 1.4.0pillow 10.0.1webp 0.2.6magick.net-q16-anycpu 13.3.0magick.net-q16-hdri-anycpu 13.3.0magick.net-q16-x64 13.3.0magick.net-q8-anycpu 13.3.0magick.net-q8-openmp-x64 13.3.0magick.net-q8-x64 13.3.0github.com/chai2010/webp 0.0.0-20250406010349-76805d5a8860github.com/chai2010/webp 1.1.2-0.20250406010349-76805d5a8860Field changes observed since this record was first indexed.