PT-2026-61636 · Libvips · Libvips

CVE-2026-35591

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions libvips versions prior to 8.18.2
Description The tiffload operation can incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, which may lead to a buffer overflow. A buffer overflow occurs when a program writes more data to a block of memory than it can hold, potentially corrupting memory or allowing arbitrary code execution.
Recommendations Update to version 8.18.2.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35591
GHSA-523X-VHFW-6R76

Affected Products

Libvips