• Sources: primary, Discourse advisory, discussion
  • Summary: Hacktron describes a heap overflow in libheif, reached through a user-supplied HEIF or AVIF image that the target service decodes, and chains it through OpenAI single sign-on to reach an internal repository, with the writeup rather than the fix being what is new today. The post names the affected 1.19.x, 1.20.x, 1.22.x and 1.23.x release families, the vulnerable 1.19.7 in the Discourse Docker image and the 1.19.8 shipped by Debian 13, and upstream v1.23.4 as the current patched release after v1.23.2 was superseded, while the Discourse advisory GHSA-vhm9-85gw-x335, published 2026-07-28 and carrying CVE-2026-32882, lists patched versions 2026.7.0, 2026.6.1, 2026.5.2 and 2026.1.6. The chain is corroborated outside the researchers' own account by that advisory, by CVE-2026-32882 and by Debian DSA-6417-1, while the wider campaign the researchers call HEIF Heist, tracing libheif across Slack, Meta, GitHub Enterprise, Ruby on Rails and Node.js frameworks including Next.js, Astro and Gatsby, rests on their account alone.
  • Why it matters: Any service that decodes user-supplied HEIF or AVIF through libheif needs the current security release, and Debian shipped vulnerable versions for months with no CVE to flag them.
  • Follow-up: Track independent confirmation of the HEIF Heist claims against the named services and frameworks.

send feedback on this story