CVE-2026-90681 | Matthias-Wandel jhead up to 3.3 EXIF Parsing exif.c Get16u out-of-bounds (Issue 98 / EUVD-2026-77197)
A vulnerability classified as problematic has been found in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read.
This vulnerability appears as CVE-2026-90681. The attack requires local access. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.