Medium severity5.5NVD Advisory· Published Jul 20, 2026· Updated Aug 19, 2026
CVE-2026-33328
CVE-2026-33328
Description
libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the gifload operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/libvips/libvips/commit/9b633e45abfcf1fc4c84847007c81805193c0969nvdPatch
- github.com/libvips/libvips/pull/4935nvdIssue TrackingPatch
- github.com/libvips/libvips/security/advisories/GHSA-r98w-4fp7-m9c7nvdVendor AdvisoryMitigation
News mentions
0No linked articles in our index yet.