PT-2026-89112 · Struktur Ag+1 · Libheif

CVE-2026-84383

·

Published

2026-08-25

·

Updated

2026-09-10

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
🚨NextJS, Sharp and ImagicMagick affected by Critical libheif vulnerability 🚨
A heap buffer overflow CVE-2026-84383 in libheif (along with 10 other vulnerabilities) has been reported to result in RCE when parsing malformed HEIC/HEIF/AVIF images.
Popular web tools parsing AVIFS like @nextjs and sharp were reported as affected. The JFrog security research team found that @ImageMagick is also affected by the vulnerability and verified a DoS POC.
Users are recommended to upgrade:
  • libheif to version 1.23.2
  • sharp to version 0.35.4
  • next.js to versions 15.5.24 or 16.3.3
🔎 Note that other popular tools utilizing libheif may be affected.

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14478
CVE-2026-84383
OPENSUSE-SU-2026:11719-1

Affected Products

Libheif