CVE-2026-58586: Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp Robert Rothenberg 24 Jul 2026 15:02 UTC

========================================================================
CVE-2026-58586                                       CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-58586
   Distribution:  Image-WebP
       Versions:  through 0.2

       MetaCPAN:  https://metacpan.org/dist/Image-WebP

Image::WebP versions through 0.2 for Perl bundle a vulnerable version
of libwebp

Description
-----------
Image::WebP versions through 0.2 for Perl bundle a vulnerable version
of libwebp.

Image::WebP does not link to the system libwebp. Instead, it uses a
bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has
multiple known vulnerabilities, including CVE-2023-4863.

Any caller that decodes an untrusted WebP image reaches the bundled
decoder. Because the library is compiled into the module, upgrading the
system libwebp does not remediate this.

Problem types
-------------
- CWE-1395 Dependency on Vulnerable Third-Party Component

Solutions
---------
Image::WebP has not been updated since 2013. Migrate to a different
solution, such as Imager with Imager::File::WEBP.

References
----------
https://metacpan.org/release/ZAPAD/Image-WebP-0.2/source/webp-src/NEWS
https://www.cve.org/CVERecord?id=CVE-2023-4863