JLSEC-2026-151

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-151.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-151.json
JSON Data
https://api.test.osv.dev/v1/vulns/JLSEC-2026-151
Upstream
  • EUVD-2026-21732
  • GHSA-j9xr-5c85-xjhm
Published
2026-04-17T15:47:23.992Z
Modified
2026-04-17T16:17:12.883389564Z
Severity
  • 4.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L CVSS Calculator
Summary
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could...
Details

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "id": "CVE-2026-40385",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-40385",
            "database_specific": {
                "status": "Analyzed"
            },
            "published": "2026-04-12T19:16:20.480Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40385",
            "imported": "2026-04-17T15:20:42.850Z",
            "modified": "2026-04-14T20:15:39.990Z"
        },
        {
            "id": "GHSA-j9xr-5c85-xjhm",
            "url": "https://api.github.com/advisories/GHSA-j9xr-5c85-xjhm",
            "modified": "2026-04-12T21:30:19Z",
            "imported": "2026-04-17T15:20:46.307Z",
            "html_url": "https://github.com/advisories/GHSA-j9xr-5c85-xjhm",
            "published": "2026-04-12T21:30:18Z"
        },
        {
            "modified": "2026-04-14T16:33:12Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-21732",
            "id": "EUVD-2026-21732",
            "published": "2026-04-12T18:16:30Z",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-21732",
            "imported": "2026-04-17T15:20:44.579Z"
        }
    ]
}
References

Affected packages

Julia / libexif_jll

Package

Name
libexif_jll
Purl
pkg:julia/libexif_jll?uuid=cdeeb48b-bcdf-5b3f-98c4-7a29487f695f

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.26+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-151.json"