CVE-2026-14454

imager: Unsigned to Signed Conversion Error (CVE-2026-14454)

criticalEPSS 0.7%

Affected

  • tonycoz/imager lt *..1.033

Description

Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

tonycozimager
1.033fixed from 1.033

Metrics

9.8
Source: nvd-v3
49.9 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.7 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-08 12:30 UTC
CWE-196, CWE-789

Weakness classes (CWE)

  • CWE-196Variant

    Unsigned to Signed Conversion Error

    The product uses an unsigned primitive and performs a cast to a signed primitive, which can produce an unexpected value if the value of the unsigned primitive can not be represented using a signed primitive.

    cwe.mitre.org →
  • CWE-789Variant

    Memory Allocation with Excessive Size Value

    The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

    cwe.mitre.org →

References & sources

Linked advisories