CVE-2026-58586
Published: July 24th, 2026
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp.
Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863.
Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.
CRITICAL
CVSS v3: 9.8
CVSS v3: 9.8
Status
| DocFilters Release | Package | State | Justification | Comment |
|---|---|---|---|---|
| 26.3 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 26.2 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 26.1 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 25.4 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 25.3 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 25.2 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 25.1 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 24.4 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 24.4.0 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 24.3 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 24.2 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 24.1 | libwebp (1.3.2) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 23.3 | libwebp (1.3.1) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 23.2 | libwebp (1.2.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 23.1 | libwebp (1.2.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 22.4 | libwebp (1.2.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 22.3 | libwebp (1.2.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 22.2 | libwebp (1.2.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 22.1 | libwebp (1.2.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 21.11 | libwebp (1.2.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 21.8 | libwebp (1.2.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 21.5.0 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 21.2.0 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.19.3667 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.18.3599 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.16.3445 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.15.3368 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.14.3263 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.13.3179 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.12.3054 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.11.3040 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.11.2990 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.10.2934 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.9.2878 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
| 11.4.8.2822 | libwebp (0.6.0) | Not Affected | Code Not Present | This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block. |
Severity score breakdown
Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
HIGH
Base Score
9.8
Base Severity
CRITICAL
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Version
3.1