CVE-2026-24660 is a heap-based buffer overflow vulnerability in LibRaw's x3f_load_huffman functionality that allows attackers to trigger memory corruption by submitting specially crafted malicious files. This vulnerability affects LibRaw Commit d20315b and potentially impacts any applications that depend on this library for image processing. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring high complexity but no user interaction or privileges. Successful exploitation could result in high-impact consequences including confidentiality breach, integrity compromise, and denial of service. The FAUCET Risk Score of 55.0/100 indicates moderate concern within the vulnerability landscape. Current exploitation status indicates this vulnerability is not actively being exploited in the wild, with no known public exploit code readily available. The vulnerability is not listed on the KEV catalog and remains on the inactive Hot List, suggesting limited community attention and real-world targeting at this time. However, the moderate FAUCET score and HIGH CVSS rating warrant monitoring and timely patching of affected LibRaw installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.22.0CPE matchmatch criteria | cpe:2.3:a:libraw:libraw:0.22.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.