Research published by Fortbridge describes CVE-2026-32740 as a heap-buffer overflow in libheif's HeifPixelImage::copy_image_to() while decoding crafted HEIF or AVIF grid images with 4:2:0 chroma planes. In a deliberately vulnerable Next.js upload application using Sharp—whose native image-processing stack includes libvips and libheif—the researchers report achieving remote code execution by leaking pixel data to bypass ASLR, corrupting a libheif plane-map structure for a constrained write primitive, and redirecting libvips' memcpy GOT entry to an internal GModule loader. The demonstrated payload was an attacker-supplied ELF shared object disguised as a JPEG, executed when loaded by the process.
The reported exploit succeeded in 20 of 20 fresh test processes on specified Ubuntu and Debian profiles, but the authors state that exploitation relies on exact native-library versions, allocator behavior, upload handling, and binary layout. A Reddit post amplified the claim but provided no independent validation, affected-version range, vendor advisory, or confirmation of exploitation in the wild. Organizations running Next.js services that accept untrusted HEIF or AVIF uploads through Sharp should identify bundled libheif versions, upgrade to libheif 1.22.0 or later and rebuild native dependencies where applicable, and isolate or disable HEIF/AVIF processing until their deployments are verified.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers described CVE-2026-32740 as a heap-buffer overflow in libheif processing crafted HEIF/AVIF grid images. In a deliberately vulnerable Next.js lab using sharp, they reported chaining a pixel-memory disclosure and libheif plane-map corruption to hijack libvips' memcpy GOT entry, load an uploaded shared object, and achieve command execution under specific tested builds.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcefortbridge.co.uk
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.