High severity7.8NVD Advisory· Published Jul 20, 2026· Updated Aug 19, 2026
CVE-2026-35591
CVE-2026-35591
Description
libvips is a fast image processing library with low memory needs. The tiffload operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fenvdPatch
- github.com/libvips/libvips/pull/4973nvdIssue TrackingPatch
- github.com/libvips/libvips/security/advisories/GHSA-523x-vhfw-6r76nvdVendor AdvisoryPatch
News mentions
0No linked articles in our index yet.