
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-49275 is an out-of-bounds read vulnerability in the CrwMap::decodeBasic() function of Exiv2, an open-source C++ library for image metadata manipulation. It affects all Exiv2 versions up to and including 0.28.8, with version 0.28.9 containing the fix. The vulnerability was discovered by OSS-Fuzz and publicly disclosed on August 30, 2026 via a GitHub Security Advisory. It carries a Low severity rating (CVSS estimate: Medium per Feedly) (GitHub Advisory).
The root cause is an out-of-bounds read (CWE-125) in the CrwMap::decodeBasic() function within the Exiv2 library, triggered when processing malformed CRW (Canon Raw) image files. The bug was identified through OSS-Fuzz fuzzing of Exiv2's fuzz targets, and while it is reproducible via the library's fuzz harness, the Exiv2 maintainers have noted they were unable to reproduce it using the standard exiv2 command-line application, suggesting exploitation may require crafted input passed directly through the library API. The vulnerability involves reading data past the end of an intended buffer during CRW metadata decoding (GitHub Advisory, OSS-Sec).
Successful exploitation of this out-of-bounds read could allow an attacker to read memory beyond the intended buffer boundaries during CRW image metadata parsing, potentially exposing sensitive in-process memory contents. The practical impact is assessed as Low by the Exiv2 maintainers, as the bug has not been demonstrated to be exploitable via the command-line tool and may be limited to applications that directly invoke the affected library function with attacker-controlled input. Availability impact (e.g., crash/denial of service) is also possible if the out-of-bounds read triggers an access violation (GitHub Advisory).
There are no known public proof-of-concept exploits, exploit kits, or reports of in-the-wild exploitation for CVE-2026-49275. The vulnerability was found through automated fuzzing (OSS-Fuzz) and has not been added to the CISA Known Exploited Vulnerabilities catalog. No EPSS score data is currently available, and no threat actor attribution has been reported (GitHub Advisory, OSS-Sec).
Exiv2 has released version 0.28.9, which patches this vulnerability. Users and downstream distributors (including Debian and Mageia, which have issued their own advisories) should upgrade to Exiv2 0.28.9 or later as soon as possible. No configuration-based workarounds have been published; upgrading to the patched version is the recommended remediation (GitHub Advisory, OSV Debian, OSV Mageia).
The vulnerability was disclosed by Exiv2 maintainer kevinbackhouse via a GitHub Security Advisory rated Low severity, with the maintainers explicitly noting the limited exploitability via the command-line application. Downstream Linux distributions including Debian and Mageia have issued their own advisories and package updates. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been observed (GitHub Advisory, OSS-Sec).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."