ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag
- Severity:
- High
Description
When parsing an image with an embedded ICC profile that contains a crafted multiLocalizedUnicodeType (mluc) tag, ExifReader can be made to allocate memory proportional to attacker-controlled fields in the tag rather than to the actual size of the input.
Recommendation
Update the exifreader package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.10.0, < 4.39.0
- Patched version(s): 4.39.0
References
Related Issues
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957
- ExifReader is vulnerable to denial of service via unbounded decompression of image metadata - CVE-2026-8814
- React Router vulnerable to Denial of Service via reflected user input in single-fetch - CVE-2026-34077
- jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder - CVE-2026-24133
You might also like:
- Tags:
- npm
- exifreader
Anything's wrong? Let us know Last updated on July 17, 2026


