{"api_version":"v1","generated_at":"2026-10-08T06:35:00+00:00","product":{"cve_count":33,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-strukturag-libheif-c95aede8bc18","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"libheif","next_cursor":null,"observations":[{"affected":"libheif: >= 1.19.0, < 1.23.3","affected_versions_present":true,"cve_id":"CVE-2026-84450","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84450","fixed":"1.23.3.","last_modified":"2026-09-21T20:50:24.867Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-gh5q-69gg-c964","primary_source":"","published":"2026-09-18T16:04:54.422Z"},{"affected":"libheif: < 1.19.6","affected_versions_present":true,"cve_id":"CVE-2026-84449","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84449","fixed":"1.19.6.","last_modified":"2026-09-22T14:52:30.772Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-2c3g-p585-8rpq","primary_source":"","published":"2026-09-18T16:03:28.532Z"},{"affected":"libheif: >= 1.19.0, < 1.23.3","affected_versions_present":true,"cve_id":"CVE-2026-84451","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84451","fixed":"1.23.3.","last_modified":"2026-09-24T21:05:25.846Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-hh47-fhqr-cj2r","primary_source":"","published":"2026-09-18T16:02:22.529Z"},{"affected":"libheif: < 1.23.2","affected_versions_present":true,"cve_id":"CVE-2026-84447","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84447","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-18T17:29:58.718Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-84447","primary_source":"","published":"2026-09-18T16:00:51.589Z"},{"affected":"libheif: >= 1.19.0, < 1.23.2","affected_versions_present":true,"cve_id":"CVE-2026-84384","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84384","fixed":"1.23.2.","last_modified":"2026-09-18T17:30:52.628Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-24wx-9w62-c96w","primary_source":"","published":"2026-09-18T15:58:21.860Z"},{"affected":"libheif: < 1.23.2","affected_versions_present":true,"cve_id":"CVE-2026-84444","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84444","fixed":"1.23.2.","last_modified":"2026-09-22T14:50:28.718Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-j264-xvrp-5v7q","primary_source":"","published":"2026-09-18T15:56:41.773Z"},{"affected":"libheif: >= 1.22.0, < 1.23.2","affected_versions_present":true,"cve_id":"CVE-2026-84383","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84383","fixed":"1.23.2.","last_modified":"2026-09-18T16:11:18.781Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497","primary_source":"","published":"2026-09-18T15:55:46.914Z"},{"affected":"libheif: < 1.23.2","affected_versions_present":true,"cve_id":"CVE-2026-84446","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84446","fixed":"1.23.2.","last_modified":"2026-09-21T20:50:38.007Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-xw34-mjcp-jqh8","primary_source":"","published":"2026-09-18T15:54:48.945Z"},{"affected":"libheif: < 1.23.2","affected_versions_present":true,"cve_id":"CVE-2026-84448","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84448","fixed":"1.23.2.","last_modified":"2026-09-24T20:58:18.659Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-p58j-h3vm-3fp5","primary_source":"","published":"2026-09-18T15:53:42.499Z"},{"affected":"< 1.23.1","affected_versions_present":true,"cve_id":"CVE-2026-62377","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62377","fixed":"1.23.1.","last_modified":"2026-08-19T18:19:50.593Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-9ww4-9v47-m7pj","primary_source":"","published":"2026-08-18T21:22:29.899Z"},{"affected":"< 1.23.1","affected_versions_present":true,"cve_id":"CVE-2026-62291","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62291","fixed":"1.23.1.","last_modified":"2026-08-21T19:11:12.114Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-xpw3-9rhw-482x","primary_source":"","published":"2026-08-18T21:21:32.182Z"},{"affected":">= 1.19.0, < 1.23.1","affected_versions_present":true,"cve_id":"CVE-2026-62292","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62292","fixed":"1.23.1.","last_modified":"2026-08-25T01:43:35.289Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-73p7-m7gg-w2jv","primary_source":"","published":"2026-08-18T21:20:24.933Z"},{"affected":"< 1.23.1","affected_versions_present":true,"cve_id":"CVE-2026-62289","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62289","fixed":"1.23.1.","last_modified":"2026-08-19T16:51:42.360Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-jc8f-p23p-5hjg","primary_source":"","published":"2026-08-18T21:19:18.107Z"},{"affected":">= 1.19.0, < 1.23.0","affected_versions_present":true,"cve_id":"CVE-2026-50142","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50142","fixed":"1.23.0.","last_modified":"2026-08-19T18:51:48.615Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-jvmp-j3cw-84mh","primary_source":"","published":"2026-08-18T21:18:03.652Z"},{"affected":">= 1.19.0, < 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-48029","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48029","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-22T15:20:39.509Z","patch_url":"https://github.com/strukturag/libheif/commit/e523ec0bf379110b7c33d4c159f8b1202d332157","primary_source":"","published":"2026-07-22T14:13:27.879Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-47709","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47709","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-22T15:06:56.971Z","patch_url":"https://github.com/strukturag/libheif/pull/1806","primary_source":"","published":"2026-07-21T21:31:14.724Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-47254","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47254","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-22T18:24:43.175Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-wqjg-4x9g-6cvg","primary_source":"","published":"2026-07-21T21:21:41.491Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-47251","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47251","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-22T13:48:12.355Z","patch_url":"","primary_source":"","published":"2026-07-21T21:18:56.870Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-47247","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47247","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-22T14:29:24.487Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-2vh6-whr3-cmq3","primary_source":"","published":"2026-07-21T21:16:59.853Z"},{"affected":">= 1.19.0, < 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-47178","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47178","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-22T15:30:57.634Z","patch_url":"","primary_source":"","published":"2026-07-21T21:09:10.999Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-47714","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47714","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-22T13:37:10.052Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-h4wm-6wwf-qvhx","primary_source":"","published":"2026-07-21T21:04:06.167Z"},{"affected":"< 1.22.1","affected_versions_present":true,"cve_id":"CVE-2026-49271","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49271","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-22T17:05:02.343Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-r7qj-cg5r-r6vf","primary_source":"","published":"2026-06-19T17:16:20.157Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-41071","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41071","fixed":"1.22.0.","last_modified":"2026-05-27T13:25:06.805Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-xj92-xjff-h8w3","primary_source":"","published":"2026-05-22T20:59:09.822Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-41069","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41069","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T12:16:13.289Z","patch_url":"","primary_source":"","published":"2026-05-22T20:49:16.735Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-32882","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32882","fixed":"1.22.0.","last_modified":"2026-07-15T01:07:28.902Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-hg7q-rjr2-8x46","primary_source":"","published":"2026-05-19T20:07:21.464Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-32741","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32741","fixed":"1.22.0.","last_modified":"2026-07-15T01:07:42.833Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-j3w5-7whq-p37q","primary_source":"","published":"2026-05-19T19:57:26.525Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-32814","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32814","fixed":"1.22.0.","last_modified":"2026-05-20T14:06:00.428Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-4m8r-34pg-rvwc","primary_source":"","published":"2026-05-19T19:49:23.211Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-32740","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32740","fixed":"1.22.0.","last_modified":"2026-07-15T01:07:45.388Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-frfr-f3vg-2g6j","primary_source":"","published":"2026-05-19T19:22:07.743Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-32739","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32739","fixed":"1.22.0.","last_modified":"2026-05-20T13:07:09.840Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-j9g7-q9hv-gq8c","primary_source":"","published":"2026-05-19T19:10:03.585Z"},{"affected":"< 1.22.0","affected_versions_present":true,"cve_id":"CVE-2026-32738","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32738","fixed":"1.22.0.","last_modified":"2026-05-19T19:38:59.260Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-7f2h-cmpf-v9ww","primary_source":"","published":"2026-05-19T19:03:48.553Z"},{"affected":"1.21.0; 1.21.1; 1.21.2","affected_versions_present":true,"cve_id":"CVE-2026-3950","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3950","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-11T20:24:59.822Z","patch_url":"","primary_source":"","published":"2026-03-11T19:02:08.446Z"},{"affected":"1.21.0; 1.21.1; 1.21.2","affected_versions_present":true,"cve_id":"CVE-2026-3949","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3949","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-11T19:38:00.870Z","patch_url":"","primary_source":"","published":"2026-03-11T18:32:09.358Z"},{"affected":"< 1.21.0","affected_versions_present":true,"cve_id":"CVE-2025-68431","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68431","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-30T22:26:20.374Z","patch_url":"https://github.com/strukturag/libheif/security/advisories/GHSA-j87x-4gmq-cqfq","primary_source":"","published":"2025-12-29T19:09:54.628Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"strukturag"}}
