Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-14454: Imager for Perl: Large Image Can Crash the Program
CVE-2026-14454
CVE-2026-14454
Summary
Imager versions before 1.033 for Perl can crash if it processes a large image. This could be exploited by an attacker to intentionally shut down the program. To stay safe, update to Imager version 1.033 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tonyc | imager | < 1.033 |
Original title
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed.
Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an...
Original description
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed.
Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process.
An attacker could craft an image with EXIF data that terminates a worker process.
Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process.
An attacker could craft an image with EXIF data that terminates a worker process.
Vulnerability type
CWE-196
CWE-789
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026