Buffer Overflow Vulnerability in libvips Image Processing Library
CVE-2026-35591
7HIGH
What is CVE-2026-35591?
The libvips image processing library, known for its efficiency and low memory usage, is vulnerable to a buffer overflow due to incorrect channel determination in the tiffload operation for JPEG and JPEG2000-encoded tiles within TIFF images. This flaw affects versions up to and including 8.18.1. It could potentially be exploited to cause unexpected behavior in applications utilizing the library. A fix was introduced in version 8.18.2 to mitigate this vulnerability.
Affected Version(s)
libvips <= 8.18.1
