Medium severity5.5NVD Advisory· Published Jul 20, 2026· Updated Aug 19, 2026
CVE-2026-35590
CVE-2026-35590
Description
libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/libvips/libvips/commit/91ebd4d35341a8353ea490392d556d582e4b846fnvdPatch
- github.com/libvips/libvips/pull/4972nvdIssue TrackingPatch
- github.com/libvips/libvips/security/advisories/GHSA-jmwm-wc68-mhwmnvdVendor Advisory
News mentions
0No linked articles in our index yet.