Memory-Safe WebP Decoding
wpd is a faster, safer WebP decoder than libwebp, designed to help secure the

wpd is a faster, safer WebP decoder than libwebp, designed to help secure the
Web from vulnerabilities like
CVE-2023-4863. At the same
time, wpd can't just maintain the status quo for speed; it offers superior
single-threaded performance, and parallelizes better across multiple threads
Source code: https://github.com/halidecx/wpd
the OS level to sandboxed browser processes. They also process complex untrusted
input data, which makes them vulnerable to memory safety bugs. CVE-2023-4863
affected potentially billions of devices running Chrome, Firefox, Signal,
Microsoft Teams, and more – CISA confirmed it was actively exploited in the
wild, and it was added to their Known Exploited Vulnerabilities catalog
thereafter. Vulnerabilities like these have serious consequences for nearly all
While libwebp is likely safer than it was in the past, it does not "solve"
memory safety by being well-fuzzed. According to the Chromium team,
their high-severity security bugs come from memory safety issues.
To address this, wpd is written in Rust, with handwritten assembly routines for
performance. The handwritten SIMD present in the decoder is carefully scoped and
checked for correctness, and largely exists in less risky places. Nonetheless,
for consumers looking to harden their environments, wpd can be compiled without
handwritten assembly; this leaves the non-SIMD code we've written entirely
verifiably memory-safe, with the only unsafe code being in the vetted
improvement over libwebp, which is written entirely in unsafe C with SIMD
We benchmarked wpd on a subset of our
1-thread, lossy: 1.19x faster
1-thread, lossless: 2.74x faster
Because our test suite mixes animated WebP content with still content, our
multi-threaded results take advantage of parallel image decoding which results
in more impressive gains there. Our single-threaded advantage is pure
These numbers come from our benchmarking harness in the wpd repository, using
Feature parity with libwebp is a target for wpd as well, as every use case that
relies on libwebp deserves an upgrade. Compared to image-webp, wpd is a proper
libwebp replacement, with some additional features included on top:
Requires demuxing the frame payload and passing it to the image decoder. Its
animation decoder returns composited canvases.
Exposed by its low-level VP8 decoder; the caller must extract the VP8 payload
from the WebP container. Its complete WebP decoder outputs RGB/RGBA.
Exposes a boolean to enable threading, rather than a requested thread count.
Format and processing rows describe still-image capabilities. libwebp includes
libwebpdemux; its composited animation API supports fewer formats and options.
wpd’s subframe mode excludes crop/scale/flip, and its partial-row API excludes
We want to give back to open source as much as possible. This project is our
third addition to our open source catalogue, joining fcvvdp and
fmetrics. Our release of wpd means we officially have more
major open source projects than closed source (Iris-WebP and the currently
unreleased Aperture). We'd like this ratio to grow even more skewed toward open
source in the future, and we'll always commit to supporting our open work as
first-class support targets, no different from our closed encoders.
To further our security goals for wpd, we are exploring partnerships with
cybersecurity firms who are interested in securing the world's most critical
software. We'd like everyone to use wpd for free today; if there's anything
stopping you, don't hesitate to let us know what it is and we'll address it (or,
We look forward to seeing people pick up wpd. It is under the most permissive
open source license we can manage, BSD 2-Clause. If you've been following our
developments, you'll be hearing from us again soon, so stay tuned – we hope you

