{"id":"CVE-2026-8814","aliases":["GHSA-rr89-w3h9-m66j"],"url":"https://o3.security/vulnerability/CVE-2026-8814","summary":"ExifReader is vulnerable to denial of service via unbounded decompression of image metadata","details":"Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly compressed zTXt chunk can cause ExifReader to materialize a disproportionately large Comment value in memory.","published":"2026-05-19T05:00:09.223Z","modified":"2026-08-12T03:51:30.414814372Z","cvss":null,"epss":{"score":0.00465,"percentile":0.38595,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"exifreader","fixedVersion":"4.39.0"}],"fix":{"url":"https://github.com/mattiasw/ExifReader/commit/5f116128adc19f674902f8bf582bfe7dd0a36375","label":"mattiasw/ExifReader@5f11612"},"references":[{"type":"WEB","url":"https://gist.github.com/yuki-matsuhashi/cad1a45d936062438b4ab24613c34c55"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-EXIFREADER-16689340"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8814.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8814"},{"type":"FIX","url":"https://github.com/mattiasw/ExifReader/commit/5f116128adc19f674902f8bf582bfe7dd0a36375"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:30.414814372Z"}}