Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an uncaught exception was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. Due to an integer overflow, the code attempts to create a huge std::vector, which causes Exiv2 to crash with an uncaught exception. This issue has been patched in version 0.28.8.
Conclusion & alert: CVE-2026-27631 is rated Low Risk (15.3/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.04%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-03 | — | 0.04% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 2.7 | 4.0 | LOW |
|
— | — | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2026-27631: 1 source package rows (exiv2); 16 state rows across 2 repos (3.23-community, edge-community); fixed 0, open 16. | https://security.alpinelinux.org/vuln/CVE-2026-27631 |
debian
|
not yet assigned | CVE-2026-27631 not yet assigned priority: Debian including 1 source packages (exiv2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 3, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2026-27631 |
gentoo
|
low | CVE-2026-27631: 1 GLSA(s) (202603-01), 1 atom(s) (media-gfx/exiv2); latest impact low. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2026-27631 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2026-27631 |
suse
|
medium | CVE-2026-27631 severity moderate: SUSE including 16 source package names (cockpit-bridge-322-slfo.1.1_2.1, cockpit-kdump-322-slfo.1.1_2.1, …), 29 product×package rows across 13 product lines (Image SL-Micro-EC2, Image SLE-Micro, … (13 product lines)): Fixed 27, First Fixed 2. | https://www.suse.com/security/cve/CVE-2026-27631/ |
ubuntu
|
medium | CVE-2026-27631 medium priority: Ubuntu including 1 source packages (exiv2), 7 status rows across 7 suites (bionic, focal, jammy, noble, questing, upstream, xenial): released 7. | https://ubuntu.com/security/CVE-2026-27631 |
| URL | Tags |
|---|---|
| https://github.com/Exiv2/exiv2/commit/659db316eef745899a778a1e0b760a971d1b69df | Patch |
| https://github.com/Exiv2/exiv2/issues/3513 | Issue Tracking |
| https://github.com/Exiv2/exiv2/pull/3514 | Issue Tracking Patch |
| https://github.com/Exiv2/exiv2/security/advisories/GHSA-p2pw-7935-c73j | Patch Vendor Advisory |