PT-2026-64315 · Libwebp+1 · Libwebp+1
CVE-2026-58586
·
Published
2026-07-24
·
Updated
2026-07-31
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Image::WebP versions prior to 0.3.0
Description
Image::WebP bundles a copy of libwebp version 0.3.0 instead of linking to the system library. This bundled version contains multiple known security flaws. The issue occurs when the module decodes an untrusted WebP image using the bundled decoder. Since the library is compiled directly into the module, updating the system-wide libwebp does not resolve the issue.
Recommendations
Update Image::WebP to version 0.3.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Image: Webp
Libwebp