Exiv2 is an image metadata library widely embedded across photography applications, image processors, and media management tools despite its narrow product focus, making it a high-impact component in the broader software supply chain. The library's vulnerability profile clusters around memory-safety and bounds-checking weaknesses—including out-of-bounds reads and writes, integer overflows, and infinite loops—reflecting the complexity of parsing diverse image formats and metadata standards. A single flaw in this library can propagate to every downstream application that depends on it, making inventory and coordinated patching across the consuming ecosystem a critical defensive task. Defenders should treat Exiv2 disclosures as supply-chain events and prioritize testing patches in applications that process untrusted image files; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exiv2 over time
Signals from CVEs in this vendor scope (124 CVEs).
124 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-26623CRITICAL Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A heap buffer overflow was found in Exiv2 versions v0.28 | Feb 18, 2025 | 9.8 | 30 | NO | NO |
CVE-2019-9144HIGH An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cpp. This can be triggered by a crafted file. It allows an att | Feb 25, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-9143HIGH An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an | Feb 25, 2019 | 8.8 | 29 | NO | NO |
CVE-2018-11531CRITICAL Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp. | May 29, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-12265HIGH Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp. | Jun 13, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-12264HIGH Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp. | Jun 13, 2018 | 8.8 | 27 | NO | NO |
CVE-2026-27596HIGH Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found | Mar 2, 2026 | 7.5 | 26 | NO | NO |
CVE-2023-44398HIGH Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28. | Nov 6, 2023 | 8.8 | 26 | NO | NO |
CVE-2021-29464HIGH Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27. | Apr 30, 2021 | 7.8 | 26 | NO | NO |
CVE-2021-29457HIGH Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27. | Apr 19, 2021 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (124 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exiv2.
Media articles that mention a CVE ID that affects a product developed by Exiv2 — matched by CVE ID, not by vendor name.