LOW
cdcseacave
CVE published 2026-09-13
CVE-2026-38332
A heap-based buffer over-read vulnerability exists in TinyEXIF before version 1.1.0. The issue is triggered by a crafted SubjectArea length and is reachable via EntryParser::Fetch methods. This vulnerability can lead to denial of service or information disclosure if exploited. Defenders should assess exposure and prioritize verification and potential upgrades. The CVE record and NVD entry provide details [truncated]