216.73.216.123

CVE-2026-3707

· Published 08/03/2026 05:16 · Modified 09/03/2026 13:35

Labels: CVE-2026-3707 2026-03-08CVE-2026-3707CWE-189[email protected]

Essential information

Published
08/03/2026 05:16
Modified
09/03/2026 13:35
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was identified in MrNanko webp4j up to 1.3.x. The affected element is the function DecodeGifFromMemory of the file src/main/c/gif_decoder.c. Such manipulation of the argument canvas_height leads to integer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The name of the patch is 89771b201c66d15d29e4cc016d8aae82b6a5fbe1. It is advisable to implement a patch to correct this issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mrnanko / webp4j cpe:2.3:a:mrnanko:webp4j:<1.3:*:*:*:*:*:*:*

References