Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.
History

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Zapad
Zapad image::webp
Vendors & Products Zapad
Zapad image::webp

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.
Title Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp
Weaknesses CWE-1395
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published: 2026-07-24T15:02:22.783Z

Updated: 2026-07-27T16:28:31.652Z

Reserved: 2026-07-01T16:57:56.074Z

Link: CVE-2026-58586

cve-icon Vulnrichment

Updated: 2026-07-27T16:28:19.782Z

cve-icon NVD

No data.

cve-icon Redhat

No data.