Vulnerabilities/

ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag

Severity:
High

Description

When parsing an image with an embedded ICC profile that contains a crafted multiLocalizedUnicodeType (mluc) tag, ExifReader can be made to allocate memory proportional to attacker-controlled fields in the tag rather than to the actual size of the input.

Recommendation

Update the exifreader package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
exifreader
Anything's wrong? Let us know Last updated on July 17, 2026