SCA: security update for exifreader (GHSA-g77h-45rf-hcx4)

medium Tenable Cloud Security Plugin ID 444840

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the
asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in
src/image-header-iso-bmff.js, where findMetaBox() and parseBox() accept an eight-byte box header without
confirming that fields required by the parsed box remain in the DataView. A valid ftyp box followed by an
empty free or unknown box can cause an unchecked full-box version read, while a truncated extended-size
box can make getBoxLength() and hasEmptyHighBits() read absent size fields. The resulting RangeError
escapes the main parsing path and can abort an application request or worker when parse errors are not
defensively caught, causing denial of service. This issue is fixed in version 4.40.1. (CVE-2026-53496)

Solution

Update the exifreader library and its related packages to version 4.40.1 or later.

See Also

https://github.com/advisories/GHSA-g77h-45rf-hcx4

Plugin Details

Severity: Medium

ID: 444840

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 7/18/2026

Updated: 9/15/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-53496

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/17/2026

Vulnerability Publication Date: 7/17/2026

Reference Information

CVE: CVE-2026-53496