{"apiVersion":"1.0","identifier":"CVE-2026-62289","description":"libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle_get_image_tiling(handle, 1, &tiling) is called. ImageItem::get_heif_image_tiling() returns already transformed dimensions, and process_image_transformations_on_tiling() applies the clean aperture transformation again. The second application passes zero to Box_clap::left_rounded(0), where image_width minus one underflows and constructs Fraction(0xFFFFFFFF, 2). Debug builds reach an assertion and abort, while release builds can return a corrupt crop and zero-width tiling result. The affected implementation spans libheif/image-items/image_item.cc, libheif/context.cc, and libheif/box.cc. This issue is fixed in version 1.23.1.","publishedAt":"2026-08-18T22:17:02","lastModifiedAt":"2026-08-19T17:19:54","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62289","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","epssProbability":0.00302,"riskScore":0.44,"affectedProduct":"libheif","affectedVersions":"<=1.23.0","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-62289","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-62289","en":"https://www.redsauce.net/en/cves/CVE-2026-62289","fr":"https://www.redsauce.net/fr/cves/CVE-2026-62289","pt":"https://www.redsauce.net/pt/cves/CVE-2026-62289","de":"https://www.redsauce.net/de/cves/CVE-2026-62289","sk":"https://www.redsauce.net/sk/cves/CVE-2026-62289","el":"https://www.redsauce.net/el/cves/CVE-2026-62289"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-62289"}}