CVE-2026-40386: Libexif Project Libexif

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

Affected products

Published 2026-04-12. Last modified 2026-06-17.