Apr 9, 2026·4 min read·66 visits
A critical heap buffer overflow in LibRaw's CR2 metadata parser allows attackers to execute arbitrary code remotely via maliciously crafted RAW image files.
CVE-2026-21413 is a critical heap-based buffer overflow in the LibRaw library, specifically within the `lossless_jpeg_load_raw` function. Triggered by maliciously crafted RAW files, the vulnerability allows for out-of-bounds memory writes due to improper validation of the `col` index in CR2Slice metadata, resulting in an unauthenticated remote code execution vector.
LibRaw is an open-source library widely deployed for reading and decoding RAW image files from digital cameras. It serves as a foundational component in numerous downstream image processing applications, including ImageMagick, GIMP, and various operating system media frameworks.
The vulnerability, designated CVE-2026-21413, is a critical heap-based buffer overflow located in the library's lossless_jpeg_load_raw() function. This function handles the decoding of lossless JPEG data embedded within specific RAW formats, predominantly Canon's CR2 format.
The flaw is classified under CWE-129 (Improper Validation of Array Index). It allows an attacker to manipulate the memory space of applications parsing untrusted image files, yielding an unauthenticated remote code execution vector.
The root cause of CVE-2026-21413 is the absence of adequate boundary checks during the processing of CR2Slice metadata. When LibRaw decodes a CR2 image, it extracts dimension and offset parameters from this metadata to reconstruct the image matrix.
Within the lossless_jpeg_load_raw() execution path, the library utilizes a col (column) index variable derived directly from the parsed CR2Slice data. The code fails to validate whether this col value exceeds the maximum bounds of the dynamically allocated heap buffer reserved for the raw image pixels.
Because the index is trusted implicitly, subsequent memory write operations use the attacker-controlled col value to calculate memory offsets. This enables arbitrary out-of-bounds write primitives on the heap, corrupting adjacent memory structures.
The vulnerable implementation processes the JPEG slices without verifying the upper limits of the structural parameters. A crafted RAW file can declare abnormally large slice dimensions, directly manipulating the parsing loops.
The fix, introduced in commit 75ed2c12a35b765b3b6ad695cc1f044f19efe644, implements strict bounds checking on the column indices before permitting any memory writes. By evaluating the parsed metadata against the known safe buffer dimensions, the patched code ensures that out-of-bounds indexing is safely aborted.
Any attempt to provide structural dimensions exceeding the allocated pixel array capacity will now trigger an early exit or error state. This structural validation neutralizes the specific metadata manipulation path leveraged by this vulnerability.
Exploitation relies on the target application invoking LibRaw to process an attacker-supplied RAW file. Since no authentication is required, any interface that accepts image uploads or processes images automatically is a viable attack vector.
An attacker constructs a specialized CR2 file where the CR2Slice metadata is strategically altered. By setting the col index to target specific offsets, the attacker forces the application to overwrite adjacent heap metadata or function pointers.
Achieving reliable remote code execution requires precise heap layout manipulation. The attacker must align the target objects in memory so that the out-of-bounds write modifies a critical data structure, redirecting the execution flow to an attacker-controlled payload.
The vulnerability carries a maximum CVSS v3.1 score of 9.8, indicating critical severity. A successful exploit results in the complete compromise of the process executing the LibRaw parsing routine.
In a typical web application scenario where user-uploaded images are processed for thumbnail generation or metadata extraction, exploitation yields unauthenticated remote code execution. The attacker inherits the privileges of the processing daemon, often leading to full system compromise or lateral movement within the network.
Alternatively, if reliable code execution fails, the memory corruption predictably leads to application crashes. This introduces a robust denial-of-service vector against automated image processing pipelines.
The definitive remediation for CVE-2026-21413 is upgrading the LibRaw library to version 0.22.1 or later. This release incorporates the upstream fix commit 75ed2c12a35b765b3b6ad695cc1f044f19efe644.
System administrators must also identify and update statically linked binaries that package older versions of LibRaw. Downstream software such as ImageMagick and GIMP should be audited and rebuilt against the updated library to ensure comprehensive protection.
If an immediate upgrade is unfeasible, administrators should restrict the uploading and processing of RAW image files, specifically .cr2 files, from untrusted sources. Executing LibRaw-based tasks within isolated sandboxes or containerized environments will limit the blast radius of a successful exploit.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
LibRaw LibRaw | < 0.22.1 | 0.22.1 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-129 |
| Attack Vector | Network |
| CVSS Score | 9.8 |
| EPSS Score | 0.00043 |
| Exploit Status | Unexploited / Theoretical |
| CISA KEV | Not Listed |
The product uses untrusted input as an array index, but it does not validate or incorrectly validates the index to ensure it references a valid position within the array.
CVE-2026-59992 is a critical broken access control vulnerability in the first-party production media adapters of Tina CMS, including next-tinacms-s3, next-tinacms-dos, next-tinacms-azure, and next-tinacms-cloudinary. The issue allows authenticated editors to escape the configured mediaRoot directory containment, facilitating unauthorized file uploads, modifications, and deletions across the entire storage bucket or container.
A Cross-Site Request Forgery (CSRF) vulnerability in the local development server of @tinacms/cli allowed malicious cross-origin pages to send state-changing HTTP requests. This issue permitted attackers to write arbitrary files into a developer's project directory or manipulate search and GraphQL indices without authorization.
A high-severity path traversal vulnerability exists in the @logto/tunnel npm package (part of the Logto repository) prior to version 0.3.9. Remote unauthenticated attackers can exploit this vulnerability to read arbitrary local files by sending crafted HTTP requests with directory traversal sequences when the static file proxy is active.
A critical stored Cross-Site Scripting (XSS) vulnerability was identified in Froxlor server administration software panel before version 2.3.8. Authenticated customers with DNS editor privileges can inject malicious JavaScript into DNS TXT records. Because the application processes these values via a raw formatting callback without context-aware HTML entity encoding, the payload executes in the security context of administrative users who view the affected domain's DNS zones.
An authenticated administrator with privileges to manage admin accounts (such as change_serversettings) can execute arbitrary SQL commands via a second-order SQL injection vulnerability. The flaw resides in Froxlor's administrative API endpoints, specifically during the handling of IP address mapping parameters which are stored as serialized arrays and later interpolated without sanitization into active database queries. This vulnerability allows high-privileged administrative attackers to compromise the database. By injecting a payload into administrative profile metadata, an attacker can extract sensitive credentials, manipulate backend settings, or potentially disrupt database integrity. The vulnerability affects all versions of Froxlor prior to 2.3.8.
CVE-2026-54543 is a DNS Resource Record (RR) Injection vulnerability in Froxlor, an open-source server administration control panel. Prior to version 2.3.8, the DomainZones.add API command failed to perform strict sanitization and validation on the user-controlled record (label) and type parameters before serializing them into BIND-compatible zone files. An authenticated customer with DNS zone management permissions can inject control characters, breaking out of the original record context to define unauthorized resource records within managed zones.