CVE-2026-30141 Details
Description
An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file.
A buffer overflow vulnerability has been identified in the Bitbank2 AnimatedGIF library, specifically in version 2.2.0. The issue arises in the DecodeLZW function during the LZW decompression process, where insufficient bounds checking allows remote attackers to craft GIF files that cause application crashes or potentially execute arbitrary code. This vulnerability has been confirmed through fuzz testing and analysis with AddressSanitizer, which revealed heap-based buffer overflows leading to memory corruption and application instability.
Users are advised to update to the latest version of the Bitbank2 AnimatedGIF library, as the vulnerability has been fixed in the commit following version 2.2.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 9, 2026CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bitbank2/AnimatedGIF/issues/115 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/bitbank2/AnimatedGIF/issues/115 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| bitbank2 AnimatedGIF | 2.2.0 (semver) <= 67cfaca |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | New CVE Received | [email protected] |
Volerion