{"id":"ECHO-36d4-e1ba-8d3c","summary":"Vulnerability is in libheif's image-sequence / ISOBMFF track\nparsing, which was added in v1.20.0. v1.19.8 — the version we\nship — has no track parsing at all (no Box_stsc / Box_stts /\nBox_saiz / TrackBox / MovieBox), so the vulnerable code is not\npresent.\n","modified":"2026-09-15T03:33:45.749348084Z","published":"2026-05-21T02:19:44.081Z","withdrawn":"2026-06-02T10:56:03.396Z","upstream":["CVE-2026-32739"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-32739"}],"affected":[{"package":{"name":"libheif","ecosystem":"Echo","purl":"pkg:deb/echo/libheif"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.19.8-1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-36d4-e1ba-8d3c.json"}}],"schema_version":"1.9.0"}