Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

LibRaw — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting LibRaw. AI-powered Chinese analysis, POCs, and references for each vulnerability.

LibRaw is a library for decoding RAW image files used in photography applications and digital forensics tools. Historically, it has been vulnerable to multiple remote code execution flaws due to buffer overflows in parsing malformed image files, as well as denial-of-service vulnerabilities. The library has also faced issues related to memory corruption and integer overflows. With 14 CVEs recorded, these vulnerabilities often stem from insufficient input validation when processing complex image structures. While no major public security incidents have been widely documented, the consistent discovery of similar vulnerability classes suggests ongoing risks for applications integrating this library without proper safeguards.

CVE IDTitleCVSSSeverityPublished
CVE-2026-20911 Libraw 安全漏洞 — LibRawCWE-131 9.8 Critical2026-04-07
CVE-2026-21413 Libraw 安全漏洞 — LibRawCWE-129 9.8 Critical2026-04-07
CVE-2026-20889 Libraw 安全漏洞 — LibRawCWE-190 9.8 Critical2026-04-07
CVE-2026-24660 Libraw 安全漏洞 — LibRawCWE-190 8.1 High2026-04-07
CVE-2026-24450 Libraw 安全漏洞 — LibRawCWE-190 8.1 High2026-04-07
CVE-2026-20884 Libraw 安全漏洞 — LibRawCWE-190 8.1 High2026-04-07
CVE-2025-43964 Libraw 安全漏洞 — LibRawCWE-1284 2.9 Low2025-04-20
CVE-2025-43962 Libraw 缓冲区错误漏洞 — LibRawCWE-125 2.9 Low2025-04-20
CVE-2025-43961 Libraw 缓冲区错误漏洞 — LibRawCWE-125 2.9 Low2025-04-20
CVE-2025-43963 Libraw 缓冲区错误漏洞 — LibRawCWE-125 2.9 Low2025-04-20
CVE-2017-6886 LibRaw 安全漏洞 — LibRaw 9.8 -2017-05-16
CVE-2017-6887 LibRaw 安全漏洞 — LibRaw 7.1 -2017-05-16
CVE-2017-6889 LibRaw-demosaic-pack-GPL2 数字错误漏洞 — LibRaw-demosaic-pack-GPL2 9.8 -2017-05-15
CVE-2017-6890 LibRaw-demosaic-pack-GPL2 缓冲区错误漏洞 — LibRaw-demosaic-pack-GPL2 9.8 -2017-05-15

This page lists every published CVE security advisory associated with LibRaw. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.