Vulnerability library
Security checkJuly 17, 2026

ExifReader is vulnerable to denial of service via unbounded decompression of image metadata

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmexifreader

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Versions of ExifReader from 4.20.0 through 4.38.1 do not bound the size of decompressed metadata blocks. When a caller invokes the asynchronous API (e.g. ExifReader.load(file) or ExifReader.load(buffer, {async: true})) on an attacker-supplied image, a small compressed chunk in the file can expand to hundreds of megabytes of memory, consuming heap and CPU until the process slows down or runs out of memory.

Recommendation

Update the exifreader package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 4.20.0, < 4.39.0
  • Patched version(s): 4.39.0

References

Could your website be exposed too?

SmartScanner can check your website for ExifReader is vulnerable to denial of service via unbounded decompression of image metadata and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 17, 2026