CVE-2023-1999: Webmproject Libwebp

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.

Affected products

  • Webmproject Libwebp: from 0.4.2, before 1.3.1 (fixed in 1.3.1)

Published 2023-06-20. Last modified 2026-06-17.