Threat reportVulnerabilityTL-2026-2938
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers via ImageMagick/libheif (GHSA-x8r2-mggj-j6wr)
Malicious HEIC Images Can Trigger Remote Code Execution on (TL-2026-2938), also tracked as GHSA-x8r2-mggj-j6wr, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-10-05. It has no confirmed attribution, affects strukturag libheif, maps to 6 MITRE ATT&CK techniques (T1005, T1059, T1078), and is covered by 9 detection rules and 12 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 0None referenced
- Techniques
- 6MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-2938
- Threat ID
- TL-2026-2938
- Also known as
- GHSA-x8r2-mggj-j6wr, GHSA-2jg2-4ch7-h545, libheif unci RCE, WordPress libheif RCE
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- web hosting, publishing, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Malicious HEIC Images Can Trigger Remote Code Execution on
Malware and tooling: libheif-unci-wordpress-rce
How Malicious HEIC Images Can Trigger Remote Code Execution on works
A heap buffer overflow in libheif's uncompressed (unci) decoder (GHSA-x8r2-mggj-j6wr, libheif 1.18.0-1.23.2, fixed in 1.23.3) can be chained with an information-leak flaw (GHSA-2jg2-4ch7-h545) to achieve code execution as the PHP-FPM user when an authenticated WordPress Author uploads crafted HEIC images that ImageMagick passes to libheif. Fortbridge demonstrated the full chain in the lab; no in-the-wild exploitation is reported and no CVE had been assigned at time of writing.
libheif is the HEIF/HEIC decoding library used across the Linux ecosystem. WordPress does not decode images itself: on upload it hands the file to an image editor to build thumbnails and read metadata, and on servers using the PHP Imagick extension the file flows WordPress -> Imagick -> ImageMagick (which recognizes HEIF) -> libheif. This places a C++ native library, parsing attacker-supplied bytes, inside the PHP-FPM worker with that worker's privileges.
GHSA-x8r2-mggj-j6wr (upstream title: heap buffer overflow in unci mixed-interleave decoding with unequal chroma bit depths) affects libheif >= 1.18.0 through 1.23.2 and is fixed in 1.23.3 (released 2026-09-01). In the uncompressed decoder's mixed-interleave YCbCr path, a malicious image can declare the Cb component as 16-bit and Cr as 8-bit; the decoder allocates each plane from its own component depth but writes both chroma outputs using the first chroma component's byte width, producing a repeated, attacker-controlled heap out-of-bounds write (CWE-787 / CWE-122). The flaw requires libheif to be built with WITH_UNCOMPRESSED_CODEC=ON and does not depend on external codecs. The upstream maintainer scored it 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); no CVE was assigned as of the cited reporting. Credits: Alex Thomas (Wordfence), poppo25-Toss, and Wordfence's Argus agentic adversarial-testing framework.
The related GHSA-2jg2-4ch7-h545 (Remote Code Execution: out-of-bounds read and write in derived-item and pixel-plane handling; CWE-125/CWE-369/CWE-787; 11 separate issues credited to Meta's Product Security team) affects libheif <= 1.23.1 and is fixed in 1.23.2 (2026-08-25). Derived items (iden/crop/overlay/grid) let an attacker build images whose logical dimensions exceed their backing planes, so consumers index planes using geometry the planes do not have.
Fortbridge's exploit chain, as documented in its write-up: (1) an authenticated WordPress Author uploads HEIC images through the Media Library; (2) disclosure images abuse GHSA-2jg2-4ch7-h545 so that neighbouring heap bytes are encoded into WordPress-generated JPEG derivatives; (3) the exploit analyses the returned pixels to fingerprint the native stack and recover glibc arena pointers and libheif/MagickCore callback pointers (e.g. CompareSplayTreeString and RelinquishMagickMemory on Debian), taking the median of returned blocks to survive lossy JPEG output; (4) an ASLR-adjusted, profile-specific unci image (Ubuntu 1024x128 mixed-interleave; Debian a 64-frame leak-preparation HEIC) is crafted, whose overflow hijacks a C++ virtual-table pointer during cleanup, with a fake vtable and command object written into a writable MagickCore data region; (5) the redirected virtual call runs a gadget chain that executes a command (id) as the PHP-FPM account. Seven slow uploads occupy PHP-FPM workers while the eighth is reserved for the trigger. Worker crashes return HTTP 503 but are not proof of success; success was verified when a later GET to a proof path (rce-proof.txt on Debian), 404 beforehand, returned 200 with uid=33(www-data). Reported success: 6 of 8 fresh PHP-FPM parent processes on Ubuntu and 22 of 24 on Debian. Separately, Wordfence's Alex Thomas reported on a clean WordPress 7.1 Media Library on x86-64 Debian copying a protected file (/etc/passwd) to an attacker-chosen destination and leaving an executing PHP file, with 29 of 30 successful attempts on warmed Apache pools; adapting to a new server configuration reportedly costs one to two days.
Exposure depends on how libheif was built, not only its version. Reported vulnerable builds: the official WordPress Docker image (libheif 1.19.8), Debian 13 trixie (1.19.8), Ubuntu 26.04 (1.21.2) and Fedora 44 (1.21.2). Reported not vulnerable: Ubuntu 24.04 LTS (1.17.6), Debian 12 bookworm (1.15.1), Alpine 3.22/3.23 (uncompressed codec not compiled in), AlmaLinux 10 (1.17.6). Exploitation requires an account with the upload_files capability (Author or higher), so the practical risk is greatest on multi-author sites and sites with open registration or compromised contributor accounts. Code runs as the PHP-FPM user (www-data in the lab). The platform marks this PATCHED upstream; hosts that have not updated the OS package or rebuilt containers, and have not restarted PHP-FPM, remain exposed. No threat actor, malware or in-the-wild exploitation has been reported; a public PoC repository exists.
MITRE ATT&CK techniques used in TL-2026-2938
Collection
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Persistence
T1505.003 Server Software Component: Web Shell
Resource Development
Affected products and versions in Malicious HEIC Images Can Trigger Remote Code Execution on
- strukturag — libheif
Vulnerable versions: 1.18.0 through 1.23.2 (GHSA-x8r2-mggj-j6wr; builds with WITH_UNCOMPRESSED_CODEC=ON); <= 1.23.1 (GHSA-2jg2-4ch7-h545)
Fixed in: 1.23.3; 1.23.4; 1.23.2 (GHSA-2jg2-4ch7-h545) - Debian — libheif (Debian 13 trixie)
Vulnerable versions: 1.19.8
Fixed in: 1.23.4-1~deb13u1 - Canonical — libheif (Ubuntu 26.04)
Vulnerable versions: 1.21.2
Fixed in: 1.23.3 or later - WordPress — WordPress Docker image / WordPress with Imagick + ImageMagick (HEIF-enabled)
Vulnerable versions: Docker image bundling libheif 1.19.8; lab-validated on WordPress 7.0 and 7.1.1
Fixed in: Rebuild from base image with libheif 1.23.3+
Remediation for Malicious HEIC Images Can Trigger Remote Code Execution on
Patches
- libheif 1.23.2 (GHSA-2jg2-4ch7-h545)
- libheif 1.23.3 (GHSA-x8r2-mggj-j6wr)
- libheif 1.23.4 (further hardening)
Immediate actions
- Upgrade libheif to 1.23.3 or later (1.23.4 is current; API/ABI compatible) via OS or hosting-provider packages; Debian shipped 1.23.4-1~deb13u1
- Restart PHP-FPM / Apache / web services after patching so the old library is unloaded from memory
- Rebuild and redeploy containers (including WordPress Docker images) from updated base images
- Check WordPress Tools > Site Health > Info > Media Handling for HEIC support to confirm exposure
Workarounds
- Disable HEIF upload types (heic, heif, heics, heifs) and block HEIC/AVIF uploads if not needed
- Use a libheif build without the uncompressed codec (WITH_UNCOMPRESSED_CODEC=OFF)
Longer-term hardening
- Process untrusted media in an isolated, disposable, least-privilege service with restricted network access
- Restrict writable paths and prevent script execution from the uploads directory
- Treat native crashes (PHP-FPM worker exits) as security events and alert on them
- Review Author-and-above accounts and open-registration settings, since exploitation needs upload_files
Weaknesses (CWE) in Malicious HEIC Images Can Trigger Remote Code Execution on
Timeline of Malicious HEIC Images Can Trigger Remote Code Execution on
- Same day as libheif 1.23.2, Next.js 15.5.24 and 16.3.3 ship fixes for CVE-2026-32740 (libheif grid-tile heap overflow reachable via sharp/AVIF, found by Hacktron), showing libheif as an actively researched attack surface in server-side image pipelines.
- libheif 1.23.2 released; GHSA-2jg2-4ch7-h545 (out-of-bounds read/write in derived-item and pixel-plane handling, 11 issues credited to Meta Product Security) published and fixed.
- libheif 1.23.3 released; GHSA-x8r2-mggj-j6wr (heap buffer overflow in unci mixed-interleave decoding, rated 9.8 critical) published and fixed. Credits: Alex Thomas (Wordfence), poppo25-Toss, Wordfence Argus.
- Configuration testing (per webhosting.today) finds vulnerable builds in the official WordPress Docker image (1.19.8), Debian 13 (1.19.8), Ubuntu 26.04 and Fedora 44 (1.21.2); Ubuntu 24.04, Debian 12, Alpine 3.22/3.23 and AlmaLinux 10 not exposed.
- libheif 1.23.4 released with further high-severity hardening fixes (unbounded item declarations, reference-cycle recursion, decoder deadlock).
- Nine libheif CVEs (scored 3.7-9.8) appear in NVD, but none describe the unci mixed-interleave overflow, which remains without a CVE.
- webhosting.today reports the critical libheif flaw is reachable through WordPress uploads and still has no CVE; 16 of 25 libheif advisories since Aug 25 lack CVEs. Wordfence's Alex Thomas demonstrated file copy and PHP execution on WordPress 7.1.
- Fortbridge publishes a full WordPress/ImageMagick/PHP-FPM exploit chain and PoC repository; Cyber Security News and GBHackers report it. Debian ships libheif 1.23.4-1~deb13u1.
Sources cited for Malicious HEIC Images Can Trigger Remote Code Execution on
- Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
- Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads
- Fortbridge - WordPress libheif RCE: Exploit Chain
- Fortbridge libheif-unci-wordpress-rce PoC repository
- libheif advisory GHSA-x8r2-mggj-j6wr: heap buffer overflow in unci mixed-interleave decoding
- libheif advisory GHSA-2jg2-4ch7-h545: RCE via out-of-bounds read/write in derived-item and pixel-plane handling
- A critical libheif bug reachable through WordPress uploads still has no CVE
- Vercel - Reproducing, disclosing and fixing the libheif vulnerability with Hacktron and the maintainers
- CVE-2026-32740 (libheif heap overflow, Next.js/sharp related)
- libheif releases (v1.23.2, v1.23.3, v1.23.4)
Detection coverage for TL-2026-2938
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2938 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.