PT-2026-64315 · Libwebp+1 · Libwebp+1

CVE-2026-58586

·

Published

2026-07-24

·

Updated

2026-07-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Image::WebP versions prior to 0.3.0
Description Image::WebP bundles a copy of libwebp version 0.3.0 instead of linking to the system library. This bundled version contains multiple known security flaws. The issue occurs when the module decodes an untrusted WebP image using the bundled decoder. Since the library is compiled directly into the module, updating the system-wide libwebp does not resolve the issue.
Recommendations Update Image::WebP to version 0.3.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58586

Affected Products

Image: Webp
Libwebp