OVERVIEW CVE-2026-21413 is a heap-based buffer overflow vulnerability affecting LibRaw in the lossless_jpeg_load_raw functionality, specifically impacting Commit 0b56545 and Commit d20315b. The vulnerability can be triggered when processing specially crafted malicious image files, allowing attackers to exploit the memory handling flaw. SEVERITY This vulnerability carries a CRITICAL severity rating with a CVSS v3.1 score of 9.8. The attack requires no user privileges, can be executed remotely over the network, and demands minimal technical complexity to exploit. The threat model involves no user interaction, and successful exploitation results in complete system compromise with high confidentiality, integrity, and availability impacts. EXPLOITATION STATUS The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and remains in an inactive status on threat tracking lists. The EPSS score of 0.0005 indicates a relatively lower probability of exploitation compared to other vulnerabilities in the wild, though the critical CVSS rating warrants immediate attention. The FAUCET Risk Score of 54.0/100 reflects moderate community concern, suggesting this should be prioritized for patching despite currently low active exploitation indicators.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.22.0CPE matchmatch criteria | cpe:2.3:a:libraw:libraw:0.22.0:*:*:*:*:*:*:* | ||
0.22.1CPE matchmatch criteria | cpe:2.3:a:libraw:libraw:0.22.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.