CVE-2026-48029: Struktur Libheif
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.
Affected products
- Struktur Libheif: from 1.19.0, before 1.22.0 (fixed in 1.22.0)
Published 2026-07-22. Last modified 2026-08-06.