Libraw is a widely embedded image-processing library used across photography, imaging, and multimedia applications to decode raw camera formats, presenting a modest but notably prominent attack surface given its position in media-processing pipelines. The vendor's vulnerability footprint skews strongly toward critical-severity outcomes, reflecting the memory-safety demands of parsing untrusted binary image data from diverse camera sensors and manufacturers. Recurring exposure centers on out-of-bounds reads and writes, buffer-boundary violations, integer overflows, and NULL-pointer dereferences—weakness classes endemic to low-level format parsing and memory manipulation in native codebases handling variable-length, vendor-specific image structures. Defenders should treat this library's advisories as high-priority for any application chain that processes user-supplied raw images, particularly web services and batch-processing systems where input validation may be insufficient. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libraw over time
Signals from CVEs in this vendor scope (65 CVEs).
65 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24660CRITICAL A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overf | Apr 7, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-24450CRITICAL An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer ov | Apr 7, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-20884CRITICAL An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. | Apr 7, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-21413CRITICAL A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can le | Apr 7, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-20911CRITICAL A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead t | Apr 7, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-20889CRITICAL A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overf | Apr 7, 2026 | 9.8 | 35 | NO | NO |
CVE-2017-14265CRITICAL A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution | Sep 11, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-6886CRITICAL An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory. | May 16, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-14608CRITICAL In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp. An attacker could possibly ex | Sep 20, 2017 | 9.1 | 30 | NO | NO |
CVE-2018-5808HIGH An error within the "find_green()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack-based buffer overflow and subsequently | Dec 7, 2018 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (65 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libraw.
Media articles that mention a CVE ID that affects a product developed by Libraw — matched by CVE ID, not by vendor name.