CVE-2026-58586

Published: July 24th, 2026
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.
CRITICAL
CVSS v3: 9.8

Status

DocFilters Release Package State Justification Comment
26.3 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
26.2 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
26.1 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
25.4 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
25.3 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
25.2 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
25.1 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
24.4 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
24.4.0 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
24.3 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
24.2 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
24.1 libwebp (1.3.2) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
23.3 libwebp (1.3.1) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
23.2 libwebp (1.2.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
23.1 libwebp (1.2.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
22.4 libwebp (1.2.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
22.3 libwebp (1.2.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
22.2 libwebp (1.2.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
22.1 libwebp (1.2.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
21.11 libwebp (1.2.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
21.8 libwebp (1.2.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
21.5.0 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
21.2.0 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.19.3667 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.18.3599 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.16.3445 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.15.3368 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.14.3263 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.13.3179 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.12.3054 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.11.3040 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.11.2990 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.10.2934 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.9.2878 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.
11.4.8.2822 libwebp (0.6.0) Not Affected Code Not Present This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module’s bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.

Severity score breakdown

Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
HIGH
Base Score
9.8
Base Severity
CRITICAL
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Version
3.1

References