PatchSiren cyber security CVE debrief
CVE-2026-47251 strukturag CVE debrief
CVE-2026-47251 is a MEDIUM severity vulnerability in libheif, a HEIF and AVIF file format decoder and encoder. The vulnerability is caused by an integer overflow in a security check added to fix CVE-2026-3949. This allows a crafted HEIF file with a VVC track to trigger an out-of-bounds heap read. The issue was introduced in commit `b97c8b5` and PR #1712, which was closed as fixed without testing edge cases. Version 1.22.0 patches the issue.
- Vendor
- strukturag
- Product
- libheif
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Users of libheif, particularly those handling HEIF and AVIF files, should be aware of this vulnerability. Developers and maintainers of applications using libheif should prioritize patching to version 1.22.0 to prevent potential exploitation.
Technical summary
The vulnerability in libheif is due to an integer overflow in a security check intended to prevent out-of-bounds heap reads. A crafted HEIF file with a VVC track can bypass this check, triggering the same vulnerability that the fix for CVE-2026-3949 aimed to prevent. This issue was introduced in a fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) but was not properly tested for edge cases, such as when `size` is near `UINT32_MAX`.
Defensive priority
Medium
Recommended defensive actions
- Apply the patch from version 1.22.0 to fix the integer overflow vulnerability.
- Review and update libheif to the latest patched version.
- Implement compensating controls such as input validation and file format checking.
- Monitor for suspicious HEIF and AVIF file processing activities.
- Perform regular inventory checks for systems and applications using libheif.
Evidence notes
The CVE record was published on 2026-07-21T22:17:12.800Z and was last modified on 2026-07-22T20:38:42.127Z. The NVD entry is currently Awaiting Analysis. The vulnerability has a CVSS score of 6.8 and is classified as MEDIUM severity.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:12.800Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.