CVE-2026-20889 is a heap-based buffer overflow vulnerability in LibRaw's x3f_thumb_loader functionality (Commit d20315b) that can be exploited through specially crafted malicious files. The vulnerability allows attackers to trigger memory corruption by providing a malicious input file to applications utilizing the affected LibRaw library component. The vulnerability carries a critical CVSS score of 9.8, reflecting a network-accessible attack vector requiring no authentication, low complexity, and no user interaction. Exploitation results in complete system compromise with high impact to confidentiality, integrity, and availability. The FAUCET risk score of 54.0/100 indicates moderate assessed risk within LibRaw's user base. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and remains on inactive status for public exploit availability. The extremely low EPSS score of 0.0005 suggests minimal current real-world exploitation probability, though the critical severity rating warrants prompt patching of affected LibRaw installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.22.0CPE matchmatch criteria | cpe:2.3:a:libraw:libraw:0.22.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.