libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 20 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libvips
Libvips libvips |
|
| Vendors & Products |
Libvips
Libvips libvips |
Mon, 20 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2. | |
| Title | Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-07-20T16:24:50.831Z
Updated: 2026-07-20T17:44:01.158Z
Reserved: 2026-04-03T21:25:12.161Z
Link: CVE-2026-35591
Updated: 2026-07-20T17:43:55.284Z
Status : Analyzed
Published: 2026-07-20T17:17:07.277
Modified: 2026-08-19T19:10:32.480
Link: CVE-2026-35591
No data.