LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-24660

CVE-2026-24660 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: April 7, 2026

LibRaw - Buffer Overflow

Published: April 7, 2026Updated: April 7, 2026Remote Exploitable

Overview

LibRaw contains a heap-based buffer overflow caused by improper handling in x3f_load_huffman functionality, letting attackers trigger heap corruption by providing a specially crafted malicious file, exploit requires attacker to supply malicious file.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can cause heap corruption leading to potential code execution or application crash.

Mitigation

Update to the latest version containing the fix.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 7, 2026

🟠 CVE-2026-24660 - High (8.1) A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulne... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-24660/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 7, 2026

🟠 CVE-2026-24660 - High (8.1) A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulne... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-24660/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-24660
Severity
High
CVSS Score
8.1
Type
buffer_overflow
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-190

CVSS Metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days