Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-pj96-35fp-cfcc CVE-2026-85715

ExifReader Denial-of-Service Flaw Lets Malicious Images Crash Node.js Applications

ExifReader versions up to 4.41.0 fail to bound memory allocation when parsing HEIC/AVIF iloc boxes, allowing a small malicious image file to exhaust memory and crash applications. Fixed in 4.41.1.

Synthesized by AI from 2 sources · updated 2 hours ago

AI summary

A denial-of-service vulnerability has been identified in ExifReader, a JavaScript library used to parse Exif metadata from image files. The flaw allows a specially crafted HEIC or AVIF image to trigger excessive memory allocation, potentially crashing applications that process untrusted images. A fix is available in version 4.41.1.

What Happened

A vulnerability (CVE-2026-85715, GHSA-pj96-35fp-cfcc) was identified in ExifReader, a JavaScript Exif metadata parser. Versions up to and including 4.41.0 do not properly limit memory allocation when parsing the 'iloc' box within HEIC or AVIF image files following the ISO-BMFF container format. A small, specially crafted image can cause the parser to allocate hundreds of megabytes of memory or exhaust available system memory, crashing the application or Node.js process handling the file.

Technical Cause

The vulnerability resides in getItems() within src/image-header-iso-bmff-iloc.js. The parser trusts attacker-controlled itemCount and extentCount values from the iloc box and allocates an extent object for every nested-loop iteration without any allocation budget. When the ISO-BMFF fields offsetSize, lengthSize, baseOffsetSize, and indexSize are all set to zero — which is a valid encoding indicating absent fields — the extent fields consume no input bytes and the parser's buffer offset never advances. This allows the loop to continue allocating objects based solely on the attacker-supplied counts, rather than being constrained by the actual size of the input data. This is classified as CWE-789 (Memory Allocation with Excessive Size Value).

Why It Matters

Any application that uses ExifReader to parse HEIC or AVIF images from untrusted sources — including web upload handlers, desktop applications, and mobile apps — can be forced into excessive memory consumption by a single small malicious file. This can terminate the hosting process (for example, a Node.js server), resulting in denial of service for all users relying on that process. The vulnerability does not require authentication or user interaction beyond the application processing the attacker-supplied image.

Who Is Affected

Developers and organizations using the ExifReader npm package in versions up to and including 4.41.0 to parse HEIC or AVIF images, particularly in contexts where image files originate from untrusted or external sources (e.g., user uploads), are affected.

Affected Versions

ExifReader versions from the initial release up to and including 4.41.0 are affected. The issue is fixed in version 4.41.1.

Fixes and Mitigation

The vendor has released ExifReader 4.41.1, which addresses the unbounded allocation issue. Users should upgrade to this version to prevent the denial-of-service condition.

Recommended Action

Update the ExifReader npm package to version 4.41.1 as soon as possible, particularly in any application that processes HEIC or AVIF image files from external or untrusted sources. Review dependency manifests and lockfiles to confirm the update is applied across all affected deployments.

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

This vulnerability has a CVSS base score of 7.5 (High), reflecting a network-exploitable, unauthenticated denial-of-service condition requiring no user interaction and causing a high impact on availability, with no impact on confidentiality or integrity. PatchBriefing's computed score of 4.9 reflects this CVSS base contribution along with small additions for the unauthenticated, remote attack vector and lack of required user interaction. There is no evidence of known exploitation or a public exploit, and no EPSS score was available to indicate real-world exploitation likelihood. A fix is already available, which further limits ongoing risk once applied.

Affected versions

exifreader <= 4.41.0
vulnerable
≥ 4.41.1
patched

Reported fixes

The vendor has released ExifReader 4.41.1, which addresses the unbounded allocation issue. Users should upgrade to this version to prevent the denial-of-service condition.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
ExifReader Denial-of-Service Flaw Lets Malicious Images Crash Node.js Applications
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email