Description
Versions of ExifReader from 4.20.0 through 4.38.1 do not bound the size of decompressed metadata blocks. When a caller invokes the asynchronous API (e.g. ExifReader.load(file) or ExifReader.load(buffer, {async: true})) on an attacker-supplied image, a small compressed chunk in the file can expand to hundreds of megabytes of memory, consuming heap and CPU until the process slows down or runs out of memory.
Recommendation
Update the exifreader package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.20.0, < 4.39.0
- Patched version(s): 4.39.0
References
Could your website be exposed too?
SmartScanner can check your website for ExifReader is vulnerable to denial of service via unbounded decompression of image metadata and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions - CVE-2026-34404
- ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag - CVE-2026-8813
- Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer - CVE-2026-41680
- path-to-regexp vulnerable to Denial of Service via sequential optional groups - CVE-2026-4926


