JLSEC-2026-152

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-152.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-152.json
JSON Data
https://api.test.osv.dev/v1/vulns/JLSEC-2026-152
Upstream
  • EUVD-2026-21734
  • GHSA-p6wp-hhx9-7jj5
Published
2026-04-17T15:47:23.992Z
Modified
2026-04-17T16:17:12.624714349Z
Severity
  • 4.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L CVSS Calculator
Summary
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote...
Details

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-40386",
            "database_specific": {
                "status": "Analyzed"
            },
            "id": "CVE-2026-40386",
            "imported": "2026-04-17T15:20:42.859Z",
            "published": "2026-04-12T19:16:20.640Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40386",
            "modified": "2026-04-14T20:43:44.283Z"
        },
        {
            "id": "GHSA-p6wp-hhx9-7jj5",
            "url": "https://api.github.com/advisories/GHSA-p6wp-hhx9-7jj5",
            "imported": "2026-04-17T15:20:46.597Z",
            "published": "2026-04-12T21:30:18Z",
            "html_url": "https://github.com/advisories/GHSA-p6wp-hhx9-7jj5",
            "modified": "2026-04-12T21:30:19Z"
        },
        {
            "id": "EUVD-2026-21734",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-21734",
            "imported": "2026-04-17T15:20:44.604Z",
            "published": "2026-04-12T18:19:08Z",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-21734",
            "modified": "2026-04-14T16:33:07Z"
        }
    ]
}
References

Affected packages

Julia / libexif_jll

Package

Name
libexif_jll
Purl
pkg:julia/libexif_jll?uuid=cdeeb48b-bcdf-5b3f-98c4-7a29487f695f

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.26+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-152.json"