CVE-2025-32025

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-32025
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32025.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-32025
Aliases
Related
Published
2025-04-08T16:15:27Z
Modified
2025-04-09T17:42:01.114180Z
Summary
[none]
Details

bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The buffer created for parsing metadata for PNG and WebP images was only bounded by their input data type, which could lead to potentially large memory allocation, and unreasonably high for image metadata. Before v0.11.0, If you didn't trust the input images, this could be abused to construct denial-of-service attacks. v0.11.0 added a 10 MB upper limit.

References

Affected packages

Git / github.com/bep/imagemeta

Affected ranges

Type
GIT
Repo
https://github.com/bep/imagemeta
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.1.0
v0.10.0
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.7.5
v0.7.6
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.9.0