# CVE-2022-4988

## Summary

- **CVE ID:** CVE-2022-4988
- **Severity:** HIGH
- **CVSS Score:** 7.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
- **CWE:** CWE-1395
- **Published:** May 11, 2026
- **Last Modified:** May 13, 2026

## Description

Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries.

Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities such as CVE-2015-0852 and CVE-2025-65803.  The library embeds other images libraries that also have known vulnerabilities.

## Affected Products

- KMX — Alien::FreeImage (0)

## References

- [CNA](https://freeimage.sourceforge.io/)
- [CNA](https://metacpan.org/release/KMX/Alien-FreeImage-1.001/source/src/Source)
- [CNA](https://nvd.nist.gov/vuln/detail/CVE-2015-0852)
- [CNA](https://nvd.nist.gov/vuln/detail/CVE-2025-65803)
- [CNA](https://github.com/kmx/alien-freeimage/issues/4)
- [CNA](https://github.com/kmx/alien-freeimage/issues/5)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 21.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._