The EXIF data format allows for defining excessively large data structures in relatively small payloads. Before v0.10.0
, If you didn't trust the input images, this could be abused to construct denial-of-service attacks.
v0.10.0
added LimitNumTags (default 5000) and LimitTagSize (default 10000) options.
{ "nvd_published_at": "2025-04-08T16:15:27Z", "cwe_ids": [ "CWE-770" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-04-09T12:57:44Z" }