CVE-2022-1507: Chafa Project Chafa

Medium severity, CVSS 5.5. EPSS: 0.9% chance of exploitation in the next 30 days.

chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file.

Affected products

Published 2022-04-27. Last modified 2026-06-17.