> GitLab Workhorse could check if the file is a valid TIFF of JPEG before passing it to ExifTool
This approach doesn't work in general. An attacker could craft a polyglot file - and in that case it's a matter of which format is tried first. Valid tiff's could potentially be processed as something entirely different.