CVE-2026-20884 is an integer overflow vulnerability in LibRaw's deflate_dng_load_raw function (Commit 8dc68e2) that can be exploited through specially crafted malicious files to trigger a heap buffer overflow. This affects LibRaw and any applications that depend on this library for image processing, particularly those handling DNG (Digital Negative) format files. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network attack vector, high complexity, and no authentication required. It poses significant risk across confidentiality, integrity, and availability, enabling potential code execution, data theft, or system compromise. However, the EPSS score of 0.0005 indicates relatively low prevalence compared to other vulnerabilities in the wild. There is no indication of active exploitation at this time, with the vulnerability absent from the Known Exploited Vulnerabilities (KEV) catalog and marked as inactive on the Hot List. Community attention appears limited based on the moderate FAUCET risk score of 55.0. Organizations should prioritize patching when updates become available but need not treat this as an immediate emergency response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.22.1CPE matchmatch criteria | cpe:2.3:a:libraw:libraw:0.22.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.