Chafa Project maintains a specialized image-to-text conversion library used in terminal and text-based rendering contexts, with its vulnerability footprint concentrated in the single Chafa product and rooted in memory-safety handling during image parsing and buffer manipulation. The recurring weakness classes—including buffer over-reads, heap-based buffer overflows, NULL pointer dereferences, and out-of-bounds reads and writes—reflect the low-level memory operations inherent to image decoding and format conversion logic. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chafa Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1507MEDIUM chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub re | Apr 27, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-2301MEDIUM Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3. | Jul 4, 2022 | 5.5 | 19 | NO | NO |
Heap-based Buffer Overflow in GitHub repository hpjansson/chafa prior to 1.12.0. | Jun 13, 2022 | 3.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chafa Project.
Media articles that mention a CVE ID that affects a product developed by Chafa Project — matched by CVE ID, not by vendor name.