CVE-2026-58586
The Perl module Image::WebP bundles an old, vulnerable copy of libwebp. Any program that decodes a WebP image can trigger the library’s bugs, which can lead to code execution or denial of service. The flaw exists in all versions of Image::WebP before 0.3.0.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Perl's Image::WebP module, any version earlier than 0.3.0, used by applications that decode WebP images.
Real-world impact
An attacker could send a crafted WebP file to a vulnerable application, potentially running arbitrary code on the host or crashing the service.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited over the network with no authentication, no user interaction, and it can compromise confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 24, 2026 · 8d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 31, 2026 · 11h agoAdvisory updatedThe NVD record was last revised.