CVE-2026-22554: Mediaarea Mediainfolib

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A heap-based buffer overflow vulnerability exists in the Channel Splitting functionality of MediaInfoLib (version(s): 26.01). A specially crafted .riff file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

Affected products

Published 2026-05-20. Last modified 2026-09-23.