Medium · 4.9 Node.js & npm GHSA-pj96-35fp-cfcc CVE-2026-85715
ExifReader Denial-of-Service Flaw Lets Malicious Images Crash Node.js Applications
ExifReader versions up to 4.41.0 fail to bound memory allocation when parsing HEIC/AVIF iloc boxes, allowing a small malicious image file to exhaust memory and crash applications. Fixed in 4.41.1.
AI summary
A denial-of-service vulnerability has been identified in ExifReader, a JavaScript library used to parse Exif metadata from image files. The flaw allows a specially crafted HEIC or AVIF image to trigger excessive memory allocation, potentially crashing applications that process untrusted images. A fix is available in version 4.41.1.
What Happened
A vulnerability (CVE-2026-85715, GHSA-pj96-35fp-cfcc) was identified in ExifReader, a JavaScript Exif metadata parser. Versions up to and including 4.41.0 do not properly limit memory allocation when parsing the 'iloc' box within HEIC or AVIF image files following the ISO-BMFF container format. A small, specially crafted image can cause the parser to allocate hundreds of megabytes of memory or exhaust available system memory, crashing the application or Node.js process handling the file.
Technical Cause
The vulnerability resides in getItems() within src/image-header-iso-bmff-iloc.js. The parser trusts attacker-controlled itemCount and extentCount values from the iloc box and allocates an extent object for every nested-loop iteration without any allocation budget. When the ISO-BMFF fields offsetSize, lengthSize, baseOffsetSize, and indexSize are all set to zero — which is a valid encoding indicating absent fields — the extent fields consume no input bytes and the parser's buffer offset never advances. This allows the loop to continue allocating objects based solely on the attacker-supplied counts, rather than being constrained by the actual size of the input data. This is classified as CWE-789 (Memory Allocation with Excessive Size Value).
Why It Matters
Any application that uses ExifReader to parse HEIC or AVIF images from untrusted sources — including web upload handlers, desktop applications, and mobile apps — can be forced into excessive memory consumption by a single small malicious file. This can terminate the hosting process (for example, a Node.js server), resulting in denial of service for all users relying on that process. The vulnerability does not require authentication or user interaction beyond the application processing the attacker-supplied image.
Who Is Affected
Developers and organizations using the ExifReader npm package in versions up to and including 4.41.0 to parse HEIC or AVIF images, particularly in contexts where image files originate from untrusted or external sources (e.g., user uploads), are affected.
Affected Versions
ExifReader versions from the initial release up to and including 4.41.0 are affected. The issue is fixed in version 4.41.1.
Fixes and Mitigation
The vendor has released ExifReader 4.41.1, which addresses the unbounded allocation issue. Users should upgrade to this version to prevent the denial-of-service condition.
Recommended Action
Update the ExifReader npm package to version 4.41.1 as soon as possible, particularly in any application that processes HEIC or AVIF image files from external or untrusted sources. Review dependency manifests and lockfiles to confirm the update is applied across all affected deployments.
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
This vulnerability has a CVSS base score of 7.5 (High), reflecting a network-exploitable, unauthenticated denial-of-service condition requiring no user interaction and causing a high impact on availability, with no impact on confidentiality or integrity. PatchBriefing's computed score of 4.9 reflects this CVSS base contribution along with small additions for the unauthenticated, remote attack vector and lack of required user interaction. There is no evidence of known exploitation or a public exploit, and no EPSS score was available to indicate real-world exploitation likelihood. A fix is already available, which further limits ongoing risk once applied.
Affected versions
- exifreader <= 4.41.0
- vulnerable
- ≥ 4.41.1
- patched
Reported fixes
The vendor has released ExifReader 4.41.1, which addresses the unbounded allocation issue. Users should upgrade to this version to prevent the denial-of-service condition.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email