PT-2026-2161 · Unknown · Bio-Formats

Ron Edgerson

·

Published

2026-01-07

·

Updated

2026-02-26

·

CVE-2026-22187

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bio-Formats versions up to and including 8.3.0
Description Bio-Formats versions up to and including 8.3.0 are susceptible to unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing. The loci.formats.Memoizer class automatically loads and deserializes memo files associated with images without validation or trust enforcement. An attacker supplying a crafted .bfmemo file alongside an image can trigger deserialization of untrusted data, potentially leading to denial of service, logic manipulation, or remote code execution if suitable gadget chains are present on the classpath. Java deserialization is a process where a byte stream is converted back into an object. In this case, the lack of validation allows an attacker to control the data being deserialized, potentially executing malicious code.
Recommendations Versions prior to 8.3.1 should be updated.

Exploit

Fix

DoS

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22187
GHSA-QJM3-CVP9-3JJ3

Affected Products

Bio-Formats