CVE-2026-3707 | MrNanko webp4j up to 1.3.x src/main/c/gif_decoder.c DecodeGifFromMemory canvas_height integer overflow
A vulnerability, which was classified as critical, was found in MrNanko webp4j up to 1.3.x. The affected element is the function DecodeGifFromMemory of the file src/main/c/gif_decoder.c. Such manipulation of the argument canvas_height leads to integer overflow.
This vulnerability is uniquely identified as CVE-2026-3707. Local access is required to approach this attack. Moreover, an exploit is present.
It is advisable to implement a patch to correct this issue.