A denial-of-service was found in Exiv2 version v0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted jpg image file.
The bug is fixed in version v0.28.6.
Issue: https://github.com/Exiv2/exiv2/issues/3333 Fixes: https://github.com/Exiv2/exiv2/pull/3335 (main branch), https://github.com/Exiv2/exiv2/pull/3345 (0.28.x branch)
Please see our security policy for information about Exiv2 security.
{
"license": "CC-BY-4.0",
"sources": [
{
"imported": "2026-08-12T14:19:47.137Z",
"database_specific": {
"status": "Analyzed"
},
"id": "CVE-2025-55304",
"published": "2025-08-29T15:15:35.950Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-55304",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-55304",
"modified": "2026-06-17T09:41:37.083Z"
},
{
"imported": "2026-08-12T14:19:52.333Z",
"id": "GHSA-m54q-mm9w-fp6g",
"html_url": "https://github.com/advisories/GHSA-m54q-mm9w-fp6g",
"url": "https://api.github.com/advisories/GHSA-m54q-mm9w-fp6g",
"published": "2025-08-29T14:59:37Z",
"modified": "2025-08-29T21:04:02Z"
},
{
"imported": "2026-08-12T14:19:48.704Z",
"id": "EUVD-2025-26206",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26206",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-26206",
"published": "2025-08-29T15:00:05Z",
"modified": "2025-08-29T15:27:17Z"
}
]
}