{"id":"ECHO-c8e7-731e-b0f8","summary":"Vulnerability is in libheif's HEIF sequence parser\n(Track::init_sample_timing_table / Track::load in\nlibheif/sequences/track.cc). This sequence / ISOBMFF track parsing was\nadded in v1.20.0; v1.19.8 — the version we ship — has no sequences/\ndirectory and no init_sample_timing_table (verified: no such file or symbol\nin the v1.19.8 source), so the vulnerable code is not present.\n","modified":"2026-07-29T18:23:42.294330534Z","published":"2026-07-15T22:42:27.021Z","withdrawn":"2026-07-15T22:42:27.021Z","upstream":["CVE-2026-47254"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-47254"}],"affected":[{"package":{"name":"libheif","ecosystem":"Echo","purl":"pkg:deb/echo/libheif"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.19.8-1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-c8e7-731e-b0f8.json"}}],"schema_version":"1.9.0"}