Discourse HEIC/HEIF image-processing patch release
Security Patch Release
Summary
Hide ▲
Show ▼
Discourse released a fix for the image-processing flaw affecting HEIC/HEIF uploads and added sandboxing to reduce exposure from malicious files. The remediation came within two days and was paired with a security advisory. The patch narrowed the risky path that routed unsupported uploads into ImageMagick/libheif decoding.
Related Happenings
Hugging Face diffusers 0.38.0 security patch release
Security Patch Release
H score25
First: 28.07.2026 18:15
Last: 28.07.2026 18:15
Sources 1
About this happening:
Hugging Face Diffusers vulnerabilities tied to trust_remote_code bypasses were disclosed by Zafran Security and later patched in diffusers 0.38.0. The flaw set, na...
Hugging Face diffusers 0.38.0 security patch release
Security Patch ReleaseAbout this happening: Hugging Face Diffusers vulnerabilities tied to trust_remote_code bypasses were disclosed by Zafran Security and later patched in diffusers 0.38.0. The flaw set, na...
Timeline
-
18.09.2026 15:45 2 articles · 2h ago
Discourse patches HEIC/HEIF image-processing flaw and adds sandboxing
Mitigation Patch UpdateDiscourse had a fix ready within two days after the libheif flaw was reported through HackerOne, added image-processing sandboxing, and published a security advisory for the HEIC/HEIF upload path that routed unsupported images into ImageMagick/libheif decoding.
Show sources
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code — www.securityweek.com — 18.09.2026 15:45
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code — www.securityweek.com — 18.09.2026 15:45