In Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp allows remote attackers to cause a denial of service (invalid memory access) via a crafted file.
"https://github.com/pypa/advisory-database/blob/main/vulns/exiv2/PYSEC-2018-147.yaml"