{"id":"ECHO-912c-d41a-c3c3","upstream":["CVE-2026-62377"],"severity":[],"modified":"2026-08-26T10:15:03.990Z","affected":[{"package":{"ecosystem":"Echo","name":"libheif"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.19.8-1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-62377"},{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-62377"}],"withdrawn":"2026-08-26T10:15:03.990Z","summary":"assert(has_sequence()) in HeifContext::get_track(). The whole sequence/\ntrack API arrived in v1.20.0: 1.19.8 has no matches for has_sequence,\nget_track, m_tracks or heif_context_get_track, no libheif/sequences/ and\nno heif_sequences.h, and context.cc is 1572 lines while the upstream\npatch targets line 2115. nm -D on the shipped libheif.so exports no\nsequence/track symbol at all. Same basis as the six entries above. Note\nDebian still lists this open for trixie - the claim rests on the code\nevidence, not their triage.\n"}