← Vulnerability feed

Vulnerability record · CVE-2026-20911 · published 7 April 2026

CVE-2026-20911: Libraw classic buffer overflow vulnerability

Libraw · Libraw

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

9.8 CVSS 3.1 Critical EPSS 0.63% · top 52.0% CWE-131 · CWE-131CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 2 tagged exploit
15 Jul 2026Last modified by NVD

Description

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20911 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24450Libraw integer overflow vulnerabilityAn integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious fi…EPSS 0.57%9.8CVE-2026-20884Libraw integer overflow vulnerabilityAn integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can l…EPSS 0.57%9.8CVE-2026-20889Libraw integer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file …EPSS 0.80%9.8CVE-2026-21413Libraw out-of-bounds write vulnerabilityA heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A speciall…EPSS 0.93%9.8CVE-2025-43964Libraw vulnerabilityIn LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.EPSS 0.41%9.8CVE-2015-8366Libraw vulnerabilityArray index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly exec…EPSS 5.1%9.8CVE-2015-8367Libraw vulnerabilityThe phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory…EPSS 5.6%9.8CVE-2017-14265Libraw memory buffer overflow vulnerabilityA Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote deni…EPSS 4.3%

Source: NIST National Vulnerability Database (record CVE-2026-20911), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.