CVE-2026-35591
Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.
| CWE | CWE-122 |
| Vendor | libvips |
| Product | libvips |
| Published | Jul 20, 2026 |
| Last Updated | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for libvips libvips
Be the first to know when new unknown vulnerabilities affecting libvips libvips are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
libvips / libvips
<= 8.18.1