CVE-2026-58586: Zapad Image::webp

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.

Affected products

  • Zapad Image::webp: before 0.3.0 (fixed in 0.3.0)

Published 2026-07-24. Last modified 2026-07-31.