Vulnerability library
Security checkJuly 17, 2026

ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmexifreader

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

ExifReader 4.40.0 can throw an uncaught RangeError: Offset is outside the bounds of the DataView while parsing crafted HEIC/AVIF files. The file only needs a valid leading ftyp box with a HEIC/AVIF major brand followed by a malformed ISO-BMFF box, such as an empty 8-byte free box or a truncated extended-size box.

Recommendation

Update the exifreader package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 4.40.0
  • Patched version(s): 4.40.1

References

Could your website be exposed too?

SmartScanner can check your website for ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 17, 2026