CVE-2026-38332: Cdcseacave Tinyexif

Low severity, CVSS 2.9. EPSS: 0.2% chance of exploitation in the next 30 days.

TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.

Affected products

  • Cdcseacave Tinyexif: before 1.1.0 (fixed in 1.1.0)

Published 2026-09-13. Last modified 2026-09-22.