Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-21413

35
FAUCET Score

OVERVIEW CVE-2026-21413 is a heap-based buffer overflow vulnerability affecting LibRaw in the lossless_jpeg_load_raw functionality, specifically impacting Commit 0b56545 and Commit d20315b. The vulnerability can be triggered when processing specially crafted malicious image files, allowing attackers to exploit the memory handling flaw. SEVERITY This vulnerability carries a CRITICAL severity rating with a CVSS v3.1 score of 9.8. The attack requires no user privileges, can be executed remotely over the network, and demands minimal technical complexity to exploit. The threat model involves no user interaction, and successful exploitation results in complete system compromise with high confidentiality, integrity, and availability impacts. EXPLOITATION STATUS The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and remains in an inactive status on threat tracking lists. The EPSS score of 0.0005 indicates a relatively lower probability of exploitation compared to other vulnerabilities in the wild, though the critical CVSS rating warrants immediate attention. The FAUCET Risk Score of 54.0/100 reflects moderate community concern, suggesting this should be prioritized for patching despite currently low active exploitation indicators.

Impacted Technologies

VendorProductVersion(s)CPE
0.22.0CPE matchmatch criteria
cpe:2.3:a:libraw:libraw:0.22.0:*:*:*:*:*:*:*
0.22.1CPE matchmatch criteria
cpe:2.3:a:libraw:libraw:0.22.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.75%
Probability of exploitation in next 30 days
EPSS Percentile
51.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0075 is in the 34th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

ubuntupatch availablevia ubuntu_usn
Product: libraw (jammy)Fixed in: 0.20.2-2ubuntu2.22.04.3
ubuntupatch availablevia ubuntu_usn
Product: libraw (noble)Fixed in: 0.21.2-2.1ubuntu0.24.04.2
ubuntupatch availablevia ubuntu_usn
Product: libraw (resolute)Fixed in: 0.21.5b-1ubuntu1.1

Vendor Advisories (1)

ubuntuUSN-8522-1

LibRaw vulnerabilities

Jul 9, 2026

References

access.redhat.com / errata/RHSA-2026:11360
access.redhat.com / errata/RHSA-2026:13284
access.redhat.com / errata/RHSA-2026:13854
access.redhat.com / errata/RHSA-2026:13860
access.redhat.com / errata/RHSA-2026:13868
access.redhat.com / errata/RHSA-2026:13870
access.redhat.com / errata/RHSA-2026:14224
access.redhat.com / errata/RHSA-2026:14655
access.redhat.com / errata/RHSA-2026:14673
access.redhat.com / errata/RHSA-2026:19345
access.redhat.com / security/cve/CVE-2026-21413
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-21413.json
talosintelligence.com / vulnerability_reports/TALOS-2026-2331
ExploitThird Party Advisory
talosintelligence.com / vulnerability_reports/TALOS-2026-2331
ExploitThird Party Advisory