VulnSea

strukturag has 12 CVEs on record. Disclosure cadence is accelerating: 12 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 11. The median CVSS is 7.4 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-125 (3) and CWE-190 (3). Most affected products: libheif (10), libde265 (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.4
Publish → KEV
Last 90 days
12 prev 0

Products

  • libheif 10
  • libde265 2
12
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

strukturag vulnerabilities

CVEs affecting strukturag, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-84451Medium· 6.5
4d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition…

Sunlitstrukturag · libheifEPSS 0.45%via NVD
CVE-2026-84450Medium· 4.3
4d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_h…

Sunlitstrukturag · libheifEPSS 0.39%via NVD
CVE-2026-84449Low· 3.7
4d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_…

Sunlitstrukturag · libheifEPSS 0.34%via NVD
CVE-2026-84448Medium· 4.0
4d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals…

Sunlitstrukturag · libheifEPSS 0.12%via NVD
CVE-2026-84447High· 7.5PoC
4d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_i…

Midnightstrukturag · libheifEPSS 0.52%via NVD
CVE-2026-84446High· 7.5
4d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_…

Twilightstrukturag · libheifEPSS 0.46%via NVD
CVE-2026-84444High· 7.4
4d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not match t…

Twilightstrukturag · libheifEPSS 0.39%via NVD
CVE-2026-84384High· 7.5PoC
4d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an effective s…

Midnightstrukturag · libheifEPSS 0.52%via NVD
CVE-2026-84383Critical· 9.8PoC
4d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplica…

Abyssalstrukturag · libheifEPSS 0.64%via NVD
CVE-2026-54241High· 7.4
1w ago

libde265 is an open source implementation of the h.265 video codec

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and …

Twilightstrukturag · libde265EPSS 0.24%via NVD
CVE-2026-54240High· 7.4
1w ago

libde265 is an open source implementation of the h.265 video codec

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflo…

Twilightstrukturag · libde265EPSS 0.24%via NVD
CVE-2026-62289Medium· 4.3
1mo ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_hand…

Sunlitstrukturag · libheifEPSS 0.30%via NVD
strukturag vulnerabilities (CVEs) · VulnSea