{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asharp_projectsharpnode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:struktur:libheif:*:*:*:*:*:*:*:*","cpe:2.3:a:sharp_project:sharp:*:*:*:*:*:node.js:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libheif (\u003c 1.23.2)","sharp (\u003c 0.35.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","image-processing","library-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Struktur","Sharp"],"content_html":"\u003cp\u003eSecurity researchers have identified multiple critical vulnerabilities within the libheif library, a dependency used by the sharp npm package for image processing. The vulnerabilities, notably tracked as CVE-2026-84383, arise during the parsing of HEIF/AVIF image formats. If an application using an affected version of sharp processes a specially crafted, malicious AVIF image, it can trigger memory corruption leading to potential remote code execution (RCE) on glibc-based Linux systems.\u003c/p\u003e\n\u003cp\u003eThe impact is contingent on how the application handles untrusted image input. While the upstream libheif vulnerability is classified as critical, the sharp package maintainers have downgraded the severity to high as sharp itself does not provide native networking features. However, the risk remains significant for any system that ingests and processes images from external or untrusted sources. Users are strongly urged to upgrade to sharp version 0.35.4 or later, which incorporates the patched libheif version 1.23.2.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could result in full remote code execution on the underlying host operating system. This vulnerability affects any service or infrastructure utilizing the sharp npm package (versions prior to 0.35.4) to decode HEIF/AVIF image files. Targeted sectors include web applications, content management systems, and image processing pipelines that accept user-submitted files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of the sharp npm package to version 0.35.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eFor environments unable to update immediately, apply the code-level blocklist to disable HEIF/AVIF decoding: sharp.block({ operation: [\u0026quot;VipsForeignLoadHeif\u0026quot;] });.\u003c/li\u003e\n\u003cli\u003eEnsure the Node.js runtime environment is compiled as a Position Independent Executable (PIE) to provide exploit mitigations against RCE attempts, noting that official Node.js binaries may lack this configuration by default.\u003c/li\u003e\n\u003cli\u003eAudit image processing pipelines to identify and isolate services currently handling untrusted AVIF or HEIF file uploads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T21:50:11Z","date_published":"2026-09-08T21:50:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sharp-libheif-vulnerabilities/","summary":"Multiple critical vulnerabilities in the libheif library, including CVE-2026-84383, enable potential remote code execution via malicious AVIF image processing in applications using the sharp npm package.","title":"Critical Remote Code Execution Vulnerabilities in libheif Affecting Sharp","url":"https://feed.craftedsignal.io/briefs/2026-09-sharp-libheif-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:sharp_project:sharp:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}