CVE-2026-84447: Strukturag Libheif
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This vulnerability is fixed in 1.23.2.
Affected products
- Strukturag Libheif: before 1.23.2 (fixed in 1.23.2)
Published 2026-09-18. Last modified 2026-09-18.