4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether exifreader is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-85715
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
MEDIUM 5.3
CVE-2026-53496
ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes
MEDIUM 5.3
CVE-2026-8814
ExifReader is vulnerable to denial of service via unbounded decompression of image metadata
HIGH 7.5
CVE-2026-8813
ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes