CRITICALNuGet

Imageflow affected by libwebp zero-day and should not be used with malicious source images.

Imageflow affected by libwebp zero-day and should not be used with malicious source images.

Published 2 years agoUpdated 5 days agoSource: OSV

Affected packages

  • ImageResizer.Plugins.Imageflowbefore 5.0.12
  • Imageflow.AllPlatformsbefore 0.10.2
  • Imageflow.NativeRuntime.osx-x86_64before 2.0.0-preview6
  • Imageflow.NativeRuntime.osx_10_11-x86_64all versions
  • Imageflow.NativeRuntime.ubuntu-x86_64before 2.0.0-preview6
  • Imageflow.NativeRuntime.ubuntu-x86_64-haswellbefore 2.0.0-preview6
  • Imageflow.NativeRuntime.ubuntu_16_04-x86_64all versions
  • Imageflow.NativeRuntime.ubuntu_18_04-x86_64all versions
  • Imageflow.NativeRuntime.ubuntu_18_04-x86_64-haswellall versions
  • Imageflow.NativeRuntime.win-x86before 2.0.0-preview6
  • Imageflow.NativeRuntime.win-x86_64before 2.0.0-preview6
  • Imageflow.NativeTool.osx-x86_64before 2.0.0-preview6
  • Imageflow.NativeTool.osx_10_11-x86_64all versions
  • Imageflow.NativeTool.ubuntu-x86_64before 2.0.0-preview6
  • Imageflow.NativeTool.ubuntu-x86_64-haswellbefore 2.0.0-preview6
  • Imageflow.NativeTool.ubuntu_16_04-x86_64all versions
  • Imageflow.NativeTool.ubuntu_18_04-x86_64all versions
  • Imageflow.NativeTool.ubuntu_18_04-x86_64-haswellall versions
  • Imageflow.NativeTool.win-x86before 2.0.0-preview6
  • Imageflow.NativeTool.win-x86_64before 2.0.0-preview6
  • Imageflow.Serverbefore 0.8.2

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Imageflow affected by libwebp zero-day and should not be used with malicious source images. | HackTribune