MEDIUM
CVE-2026-47963
CVSS
5.5
Description
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Summary dbcve.org
DNG SDK versions 1.7.1 2536 and earlier contain an out-of-bounds read vulnerability that allows disclosure of sensitive memory contents when a victim opens a specially crafted malicious DNG file.
Mitigation
Avoid opening untrusted or unverified DNG files; apply vendor patches to the DNG SDK once released and rebuild any applications that integrate the affected SDK version.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
0.17%
Probability of exploitation in next 30 days
6.2th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.