CVE-2025-32025
Last modified
CVE-2025-32025 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The buffer created for parsing metadata for PNG and WebP images was only bounded by their input data type, which could lead to potentially large memory allocation, and unreasonably high for image metadata. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The buffer created for parsing metadata for PNG and WebP images was only bounded by their input data type, which could lead to potentially large memory allocation, and unreasonably high for image metadata. Before v0.11.0, If you didn't trust the input images, this could be abused to construct denial-of-service attacks. v0.11.0 added a 10 MB upper limit.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-32025?
How severe is CVE-2025-32025?
How do I fix CVE-2025-32025?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-3202A vulnerability classified as critical has been found in age…9.1
- CVE-2025-32020The crud-query-parser library parses query parameters from H…9.3
- CVE-2025-32021Weblate is a web based localization tool. Prior to version 5…7.5
- CVE-2025-32022Finit provides fast init for Linux systems. Finit's urandom …4.6
- CVE-2025-32023Redis is an open source, in-memory database that persists on…7.8
- CVE-2025-32024bep/imagemeta is a Go library for reading EXIF, IPTC and XMP…6.9
- CVE-2025-32026Element Web is a Matrix web client built using the Matrix Re…3.8
- CVE-2025-32027Yii is an open source PHP web framework. Prior to 1.1.31, yi…6.1
- CVE-2025-32028HAX CMS PHP allows you to manage your microsite universe wit…9.9
- CVE-2025-32029ts-asn1-der is a collection of utility classes to encode ASN…6.9
- CVE-2025-3203A vulnerability classified as problematic was found in Tenda…5.3
- CVE-2025-32030Apollo Gateway provides utilities for combining multiple Gra…7.5
Are you affected by CVE-2025-32025?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
