{"id":"ECHO-0bd8-3c77-95c2","summary":"Vulnerability is in libheif's image-sequence / ISOBMFF track\nparsing, which was added in v1.20.0. v1.19.8 — the version we\nship — has no track parsing at all (no Box_stsc / Box_stts /\nBox_saiz / TrackBox / MovieBox), so the vulnerable code is not\npresent.\n","modified":"2026-09-15T03:33:45.905544634Z","published":"2026-05-26T09:52:21.520Z","withdrawn":"2026-06-02T10:56:03.396Z","upstream":["CVE-2026-41071"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-41071"}],"affected":[{"package":{"name":"libheif","ecosystem":"Echo","purl":"pkg:deb/echo/libheif"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.19.8-1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-0bd8-3c77-95c2.json"}}],"schema_version":"1.9.0"}