Logo
vulnerabilityCVE-2026-35591
Name
CVE-2026-35591
Source
NVD ( link)Debian ( link)
Description
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
vips
Exploitable

Vulnerability Ratings#


7
CVSSv4
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
8.17.2
Exploitable
buildroot
master
8.18.0
Exploitable
openwrt
master
8.18.2-r1
Not Affected