CVE-2026-84447High· 7.5▾ MidnightPoC availablelibheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_i…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
0.5%
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This vulnerability is fixed in 1.23.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84384High· 7.5libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84383Critical· 9.8libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84448Medium· 4.0libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84444High· 7.4libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84446High· 7.5libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84451Medium· 6.5libheif is a HEIF and AVIF file format decoder and encoder