Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp
Summary
| CVE | CVE-2026-58586 |
|---|---|
| State | PUBLISHED |
| Assigner | CPANSec |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-24 15:18:44 UTC |
| Updated | 2026-07-24 15:18:44 UTC |
| Description | Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this. |
Risk And Classification
Problem Types: CWE-1395 CWE-1395 Dependency on Vulnerable Third-Party Component
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cve.org/CVERecord | 9b29abf9-4ab0-4765-b253-1875cd9b441e | www.cve.org | |
| metacpan.org/release/ZAPAD/Image-WebP-0.2/source/webp-src/NEWS | 9b29abf9-4ab0-4765-b253-1875cd9b441e | metacpan.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Image::WebP has not been updated since 2013. Migrate to a different solution, such as Imager with Imager::File::WEBP.
There are currently no legacy QID mappings associated with this CVE.