CVE-2026-84450
Last modified
CVE-2026-84450 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_handle_get_image_tiling().
Description
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_handle_get_image_tiling(). Box_clap::left_rounded() or Box_clap::top_rounded() passes the image dimension minus one to Fraction::Fraction(), whose uint32_t constructor uses an assertion as input validation, causing assert-enabled builds to abort. Release builds can instead compute invalid crop geometry, and the tiling API returns dimensions that the normal decode security limits reject. This issue is fixed in version 1.23.3.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-84450?
How severe is CVE-2026-84450?
How do I fix CVE-2026-84450?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84445gRPC-Go is the Go language implementation of gRPC. Prior to …8.7
- CVE-2026-84446libheif is a HEIF and AVIF file format decoder and encoder. …7.5
- CVE-2026-84447libheif is a HEIF and AVIF file format decoder and encoder. …7.5
- CVE-2026-84448libheif is a HEIF and AVIF file format decoder and encoder. …4
- CVE-2026-84449libheif is a HEIF and AVIF file format decoder and encoder. …3.7
- CVE-2026-8445justhtml versions <= 1.11.0 (fixed in 1.12.0) do not suffici…9.8
- CVE-2026-84451libheif is a HEIF and AVIF file format decoder and encoder. …6.5
- CVE-2026-84452Windows ML CLI is a command line tool for building portable,…8.6
- CVE-2026-8446IBM Langflow OSS 1.0.0 through 1.10.3 contain an authenticat…7.5
- CVE-2026-84469fastify versions before 5.12.2 decide whether to compile a r…7.5
- CVE-2026-8447IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored c…6.1
- CVE-2026-84470A flaw was found in Ansible Automation Platform's automation…6.4
Are you affected by CVE-2026-84450?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
