CVE-2026-90682 | Matthias-Wandel jhead up to 3.3 WebP EXIF gpsinfo.c ProcessGpsInfo TAG_GPS_LAT/TAG_GPS_LONG heap-based overflow (Issue 99)
A vulnerability classified as problematic was found in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-90682. An attack has to be approached locally. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More