Logo
vulnerabilityCVE-2026-33327
Name
CVE-2026-33327
Source
NVD ( link)Debian ( link)
Description
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libvips
Exploitable

Vulnerability Ratings#


7
CVSSv4
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
8.18.0
Exploitable
openwrt
master
8.18.2-r1
Not Affected
openwrt
openwrt-25.12
8.17.1-r1
Exploitable