bio-formats vulnerabilities
CVEs whose affected-version data names the bio-formats package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-22187High· 7.8PoCBio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing
Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing. The loci.formats.Memoizer class automatically loads and deserializes mem…
▾ Midnightopenmicroscopy · bio-formatsEPSS 0.51%via NVD
CVE-2026-22186High· 7.1PoC⚖ disputedBio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF)
Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser uses an insecurely configured DocumentBuilderFactory when pro…
▾ Midnightopenmicroscopy · bio-formatsEPSS 0.17%via NVD