Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-20884

36
FAUCET Score

CVE-2026-20884 is an integer overflow vulnerability in LibRaw's deflate_dng_load_raw function (Commit 8dc68e2) that can be exploited through specially crafted malicious files to trigger a heap buffer overflow. This affects LibRaw and any applications that depend on this library for image processing, particularly those handling DNG (Digital Negative) format files. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network attack vector, high complexity, and no authentication required. It poses significant risk across confidentiality, integrity, and availability, enabling potential code execution, data theft, or system compromise. However, the EPSS score of 0.0005 indicates relatively low prevalence compared to other vulnerabilities in the wild. There is no indication of active exploitation at this time, with the vulnerability absent from the Known Exploited Vulnerabilities (KEV) catalog and marked as inactive on the Hot List. Community attention appears limited based on the moderate FAUCET risk score of 55.0. Organizations should prioritize patching when updates become available but need not treat this as an immediate emergency response.

Impacted Technologies

VendorProductVersion(s)CPE
0.22.1CPE matchmatch criteria
cpe:2.3:a:libraw:libraw:0.22.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.45%
Probability of exploitation in next 30 days
EPSS Percentile
37.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0045 is in the 14th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

ubuntupatch availablevia ubuntu_usn
Product: libraw (jammy)Fixed in: 0.20.2-2ubuntu2.22.04.3
ubuntupatch availablevia ubuntu_usn
Product: libraw (noble)Fixed in: 0.21.2-2.1ubuntu0.24.04.2
ubuntupatch availablevia ubuntu_usn
Product: libraw (resolute)Fixed in: 0.21.5b-1ubuntu1.1

Vendor Advisories (1)

ubuntuUSN-8522-1

LibRaw vulnerabilities

Jul 9, 2026

References

talosintelligence.com / vulnerability_reports/TALOS-2026-2364
ExploitThird Party Advisory
talosintelligence.com / vulnerability_reports/TALOS-2026-2364
ExploitThird Party Advisory