CVE-2026-47247Struktur · Libheif
Vulnerability data via NVD (ingested)
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-47247http.html:"/wp-content/plugins/libheif/"product:"Struktur Libheif"http.html:"Libheif"More intel sources (5)
vuln:CVE-2026-47247vulnerabilities.cve_id: CVE-2026-47247CVE-2026-47247CVE-2026-47247"CVE-2026-47247" exploit -site:nvd.nist.gov