CVE-2026-33327
Possible integer overflow leading to potential heap-based buffer overflow
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
| CWE | CWE-190 |
| Vendor | libvips |
| Product | libvips |
| Published | Jul 20, 2026 |
| Last Updated | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for libvips libvips
Be the first to know when new unknown vulnerabilities affecting libvips libvips are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
libvips / libvips
<= 8.18.0