CVE-2026-14454
CRITICALDescription
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.
Is your site exposed to CVE-2026-14454?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| tonycoz | imager |
References
Frequently Asked Questions
What is CVE-2026-14454? +
How severe is CVE-2026-14454? +
What products are affected by CVE-2026-14454? +
How do I check if I'm vulnerable to CVE-2026-14454? +
Related Vulnerabilities
Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera …
The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified …