A high-severity vulnerability tracked as CVE-2026-51235 has been disclosed in LibRaw 0.21, affecting the stretch() function in src/libraw_cxx.cpp and the fuji_rotate() function in src/decoders/fuji.cpp. The flaw is classified as CWE-122 and described as a buffer overflow that could allow compromise of confidentiality, integrity, and availability. The CVSS v3.1 vector published for the issue is AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating remote exploitation is possible with low attack complexity but requires user interaction.
The CVE record was updated with SSVC metadata stating that proof-of-concept exploitation exists, automation is not currently indicated, and the technical impact is total. Public references tied to the disclosure include the LibRaw project and a GitHub advisory repository, where an update for CVE-2026-51235 was also posted, signaling active tracking of the issue as defenders assess exposure in applications that process raw image files through the affected library.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-51235 was updated to add a CVSS v3.1 vector, classify the issue as CWE-122, and include SSVC metadata indicating proof-of-concept exploitation, no automation, and total technical impact. The vulnerability affects LibRaw 0.21 and is described as a buffer overflow in the stretch() and fuji_rotate() functions.
A GitHub repository entry for CVE-2026-51235 was updated by the account "programmervuln" in commit d3d42a6. The available snippet does not include additional technical details beyond the existence of the update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.