CVE-2026-47247

Source
https://cve.org/CVERecord?id=CVE-2026-47247
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47247.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47247
Aliases
  • GHSA-2vh6-whr3-cmq3
Downstream
Related
Published
2026-07-21T21:16:59.853Z
Modified
2026-07-23T08:25:14.708414Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation
Details

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47247.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200",
        "CWE-226",
        "CWE-682",
        "CWE-908"
    ]
}
References

Affected packages

Git / github.com/strukturag/libheif

Affected ranges

Type
GIT
Repo
https://github.com/strukturag/libheif
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.22.0"
        }
    ]
}

Affected versions

v1.*
v1.1.0
v1.10.0
v1.11.0
v1.12.0
v1.13.0
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.16.0
v1.16.1
v1.16.2
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.17.5
v1.17.6
v1.18.0
v1.18.0-rc1
v1.19.0
v1.19.1
v1.19.2
v1.19.3
v1.19.4
v1.19.5
v1.2.0
v1.20.0
v1.20.1
v1.21.0
v1.21.1
v1.21.2
v1.3.0
v1.3.1
v1.3.2
v1.7.0
v1.8.0
v1.9.0
v1.9.1

Database specific

vanir_signatures
[
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "175107675317900759648359576881034358256",
                "220432159010798240840908416937024023837",
                "268268967745545109707798594937166387611",
                "253707932335489477155115861206639265538",
                "199679408075604976163979654915891773303",
                "175107675317900759648359576881034358256",
                "220432159010798240840908416937024023837",
                "268268967745545109707798594937166387611",
                "286778284410146987248233194002847271266",
                "178248309108630471590778685235254536836"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/strukturag/libheif/commit/0c81a846b7401dbdb7118afd0761057f21e43511",
        "signature_type": "Line",
        "target": {
            "file": "tests/uncompressed_box.cc"
        },
        "id": "CVE-2026-47247-91619f1d",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-23T08:25:14Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47247.json"