CVE-2026-58586

Published: Lug 24, 2026 Last Modified: Lug 24, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp.

Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863.

Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.

https://metacpan.org/release/ZAPAD/Image-WebP-0.2/source/webp-src/NEWS
https://www.cve.org/CVERecord?id=CVE-2023-4863