CVE-2026-32740 is a heap-based out-of-bounds write in libheif grid-tile compositing, affecting versions 1.21.2 and earlier. A crafted HEIF or AVIF image containing a 1×4 grid of odd-height tiles can cause chroma-plane row calculations to write 64 bytes of attacker-controlled Cb/Cr pixel data beyond a chroma-plane heap allocation during normal decoding with the default build configuration. The vulnerable behavior is associated with tile copying into a grid image, including the HeifPixelImage::copy_image_to() path. A reported, build-specific exploit chain further uses memory disclosure and plane-map corruption to obtain a constrained write primitive and execute code in a narrowly profiled Next.js, sharp, libvips, and libheif deployment; this chain depends on exact native-library versions, allocator behavior, upload handling, and binary layout.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 47-file repository is a working, profile-driven remote RCE proof of concept for CVE-2026-32740 in libheif AVIF grid processing as reached through a deliberately vulnerable Next.js/sharp application. Its primary entry point, exploit.py, repeatedly uploads an AVIF disclosure image and retrieves its optimized PNG output. Python classifiers inspect returned alpha-channel pixels for multiple libvips-relative pointers, select exactly one supported native-stack profile and ASLR base, and fail closed on absent or ambiguous evidence. Heap-calibration code then obtains the required two-byte fake-node selector before generating the destructive payload. The final chain in rce_payload.py creates a four-row AVIF grid designed to overflow a chroma plane, redirect the Cr plane, and write a library path immediately before libvips memcpy@GOT while replacing that GOT entry with the computed address of libvips's internal g_module_open_full loader. callback/callback.c is compiled locally into an ELF shared object, uploaded as x.jpg, and loaded by the hijacked call. Its constructor runs only /usr/bin/id and returns the proof output over a TCP callback with a per-attempt token. The repository explicitly indicates that exploitation normally terminates the target process. Supporting components include avif_grid.py for controlled AVIF/ISO-BMFF construction, strict profile manifests for stock, Ubuntu PIE, and Debian PIE native stacks, offline artifact verification, heap/layout diagnostics, regression tests, evidence from repeated fresh-process runs, and Dockerfiles for intentionally vulnerable Debian 13 and Ubuntu 26.04 labs. The lab exposes POST /api/upload and GET /api/optimize?file=NAME, stores uploads under uploads/, and processes selected files with sharp. The exploit is highly version- and layout-specific rather than a general-purpose exploit framework module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A claimed remote-code-execution vulnerability affecting a PIE-enabled Next.js/Node.js stack using sharp and libheif. The referenced description attributes exploitation to a pixel leak, a chosen-address write, and memcpy GOT hijacking.
A heap-buffer overflow in libheif's HEIF/AVIF grid-image tile-copying logic. Incorrect independent chroma-row rounding can produce an out-of-bounds controlled write. In the deliberately vulnerable Next.js/sharp test application, the report demonstrates remote code execution by combining the overflow with a libvips address disclosure, forged libheif plane metadata, a GOT overwrite, and loading an uploaded shared library.
A heap-buffer-overflow write vulnerability in libheif grid tile compositing affecting versions 1.21.2 and prior, triggered by a crafted HEIF/AVIF file during normal image decoding.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.