CVE-2026-58586
Description
Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp.
Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863.
Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| ZAPAD | Image::WebP | — | 0 ≤ 0.2 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-1395 | cna | CWE-1395 Dependency on Vulnerable Third-Party Component |
References (2)