Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-14454— Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed

Quick assessment

Affected
TONYC Imager
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

tony cook imager是tony cook个人开发者开源的一个图像处理程序。 Tony Cook imager 1.033之前版本存在安全漏洞,该漏洞源于将无符号EXIF IFD条目计数视为有符号数,导致大EXIF IFD条目计数值被错误处理为负数,试图分配近地址空间大小的内存块失败并终止进程。攻击者可能利用特制图像数据终止工作进程。

AI Predicted 5.5 Difficulty: Easy EPSS 0.66% · P50

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProduct Version RangeStatus
TONYC Imager < 1.033 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14454

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed
Source: CVE Program / CVE List V5
Vulnerability Description
Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
无符号至有符号转换错误
Source: CVE Program / CVE List V5
Vulnerability Title
Tony Cook imager 数字错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
tony cook imager是tony cook个人开发者开源的一个图像处理程序。 Tony Cook imager 1.033之前版本存在安全漏洞,该漏洞源于将无符号EXIF IFD条目计数视为有符号数,导致大EXIF IFD条目计数值被错误处理为负数,试图分配近地址空间大小的内存块失败并终止进程。攻击者可能利用特制图像数据终止工作进程。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
TONYC Imager 0 ~ 1.033 -

II. Public POCs for CVE-2026-14454

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14454

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-14454 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-14454

No comments yet


Leave a comment