CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-14454

Critical · CVSS 9.8

Imager (Perl) — Signed/Unsigned Integer Misinterpretation leading to excessive memory allocation DoS (CWE-196, CWE-789)

CVSS
9.8
nvd
EPSS
0.39%
31th pct
KEV
No
Class
oss containerizable
CWE-196, CWE-789

Description

Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.

Search profile — drives PoC discovery

Symbols EXIF_IFDifd_entry_countexif_entry_counti_exif_readtga_exifimexifimager_exifallocunsignedsignedIFDTIFF_LONGexif_ifd_parseimager_read_exif
Keywords CVE-2026-14454Imager Perl EXIF IFD signed unsigned integerImager before 1.033 EXIF DoSImager EXIF entry count negative allocationtonycoz imager 06f01a5d0fd591259aeba589370d6888384a6b6dImager Perl worker process kill EXIFImager 1.033 patch EXIF IFDCWE-196 CWE-789 Imager Perl
Versions: < 1.033

References

Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z