exiv2 vulnerabilities
CVEs whose affected-version data names the exiv2 package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2025-55304LowExiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
▾ Sunlitexiv2 · exiv2EPSS 0.24%via OSV
CVE-2025-54080LowExiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
▾ Sunlitexiv2 · exiv2EPSS 0.14%via OSV
CVE-2025-26623MediumExiv2 allows Use After Free
Exiv2 allows Use After Free
▾ Sunlitexiv2 · exiv2EPSS 0.92%via OSV
CVE-2024-24826Medium· 5.5Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder
Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder
▾ Sunlitexiv2 · exiv2EPSS 0.24%via OSV
CVE-2024-25112Medium· 5.5Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder
Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder
▾ Sunlitexiv2 · exiv2EPSS 0.22%via OSV