CYBERSECURITYTRACKER
TRACKING6,994 stories in this site build1,470 vulnerability news stories in this site build
Permanent story citation

CVE-2026-73638: Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7714

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-73638: Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd

CVE-2026-73638 affects Imager, a Perl image processing module, in versions 0.45_02 through 1.034. The vulnerability allows reading outside the EXIF block due to unchecked start offsets in the tiff_load_ifd function when processing TIFF files.

Why it matters: Developers and systems using Imager to process untrusted TIFF images face potential information disclosure; upgrade to version 1.035 or later.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary