Description
When parsing an image with an embedded ICC profile that contains a crafted multiLocalizedUnicodeType (mluc) tag, ExifReader can be made to allocate memory proportional to attacker-controlled fields in the tag rather than to the actual size of the input.
Recommendation
Update the exifreader package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.10.0, < 4.39.0
- Patched version(s): 4.39.0
References
Could your website be exposed too?
SmartScanner can check your website for ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957
- ExifReader is vulnerable to denial of service via unbounded decompression of image metadata - CVE-2026-8814
- React Router vulnerable to Denial of Service via reflected user input in single-fetch - CVE-2026-34077
- jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder - CVE-2026-24133


