Logo
vulnerabilityCVE-2026-3147
Name
CVE-2026-3147
Source
NVD ( link)Debian ( link)
Description
A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been made public and could be used. The patch is identified as b3ab458a25e0e261cbd1788474bbc763f7435780. It is advisable to implement a patch to correct this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libvips
Exploitable

Vulnerability Ratings#


1.9
CVSSv4
5.3
CVSSv31
7.8
CVSSv31
4.3
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
8.18.0
Exploitable
openwrt
master
8.18.2-r1
Not Affected
openwrt
openwrt-25.12
8.17.1-r1
Exploitable