Skip to content
esriCVE-2026-10758

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.

High7.5CVE-2026-10758 · Published Sep 25, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Lerc
Vendor
all versionsNo fix yet
Details and references

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker who can pass specifically crafted attacker controlled imagery to an application that uses LERC to crash the application, leading to a denial of service.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
no source yet
Weakness
CWE-190

More esri advisories

All
DateAdvisory
Aug 21There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.
CVE-2026-69233Medium5.5no fix yet
Aug 21There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.
CVE-2026-69234Medium6.1no fix yet
Aug 21There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.
CVE-2026-69235Medium6.1no fix yet
Aug 21There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.
CVE-2026-69236Medium6.1no fix yet
Aug 21There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.
CVE-2026-69237Low3.8no fix yet
Aug 21There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.
CVE-2026-69238Low3.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.