CVE-2026-5318 describes an out-of-bounds write vulnerability in the JPEG DHT Parser component (HuffTable::initval function) of LibRaw versions up to 0.22.0. This medium-severity vulnerability (CVSS 4.3) can be exploited remotely with low attack complexity, requiring user interaction, and primarily impacts availability. Although not yet in CISA's Known Exploited Vulnerabilities catalog, a public exploit has been made available, indicating a heightened risk of future attacks. Organizations using LibRaw are advised to upgrade to version 0.22.1 to mitigate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.22.1CPE matchmatch criteria | cpe:2.3:a:libraw:libraw:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.