CVE-2025-32024 Information
Apr 09, 2025
cve
Description
bep/imagemeta is a Go library for reading EXIF IPTC and XMP image meta data from JPEG TIFF PNG and WebP files. The EXIF data format allows for defining excessively large data structures in relatively small payloads. Before v0.10.0 If you didn’t trust the input images this could be abused to construct denial-of-service attacks. v0.10.0 added LimitNumTags (default 5000) and LimitTagSize (default 10000) options.
Reference
https://github.com/bep/imagemeta/commit/4fd89616d8bf7f9bb892360d3fb19080ec2b4602 https://github.com/bep/imagemeta/security/advisories/GHSA-q7rw-w4cq-2j6w
Share on: