PT-2026-61635 · Libvips · Libvips

CVE-2026-35590

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libvips versions prior to 8.18.2
Description The EXIF decoder fails to verify the range of EXIF tag groups before passing data to libexif. This lack of validation can lead to a null pointer dereference, which is a condition where the software attempts to read from a memory address that is null, resulting in a crash.
Recommendations Update to version 8.18.2.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35590
GHSA-JMWM-WC68-MHWM

Affected Products

Libvips