CVE-2026-102504
Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. N
CVSS
7.5
High
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Published: Oct 1, 2026 · Last modified: Oct 1, 2026 · CWE-190 · CWE-789
0.4%EPSS · 30 days0.4%
2026-10-022026-10-04
Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit.
- github.comhttps://github.com/tonycoz/imager/commit/21b0df9eef1dffe1fdcd3706bfea9f1338031679.patch
- github.comhttps://github.com/tonycoz/imager/security/advisories/GHSA-g549-r73g-x7x6
- metacpan.orghttps://metacpan.org/release/TONYC/Imager-1.037/changes
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/10/01/9
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-79113—2.8%
——1OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.2dCVE-2026-1036294.3 MED6.7%
——2Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-1036214.3 MED6.7%
——2Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-83745—34.6%
——10Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift
nodejs and D lang bindings.
Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again.
This issue affects Apache Thrift before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.3dCVE-2026-83632—29.4%
——9Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.3dCVE-2026-66837—19.6%
——6Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.3d