PT-2026-89112 · Struktur Ag+1 · Libheif
CVE-2026-84383
·
Published
2026-08-25
·
Updated
2026-09-10
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
🚨NextJS, Sharp and ImagicMagick affected by Critical libheif vulnerability 🚨
A heap buffer overflow CVE-2026-84383 in libheif (along with 10 other vulnerabilities) has been reported to result in RCE when parsing malformed HEIC/HEIF/AVIF images.
Popular web tools parsing AVIFS like @nextjs and sharp were reported as affected. The JFrog security research team found that @ImageMagick is also affected by the vulnerability and verified a DoS POC.
Users are recommended to upgrade:
- libheif to version 1.23.2
- sharp to version 0.35.4
- next.js to versions 15.5.24 or 16.3.3
🔎 Note that other popular tools utilizing libheif may be affected.
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libheif