๐Ÿ” CVE Alert

CVE-2026-70651

UNKNOWN 0.0

libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3.

CWE CWE-680
Vendor libvips
Product libvips
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for libvips libvips

Be the first to know when new unknown vulnerabilities affecting libvips libvips are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

libvips / libvips
< 8.18.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/libvips/libvips/security/advisories/GHSA-7p29-wg2h-36q4 github.com: https://github.com/libvips/libvips/pull/5040 github.com: https://github.com/libvips/libvips/commit/05719ca3d5852acdeb6714de2e8e769c9a5d2c11 github.com: https://github.com/libvips/libvips/releases/tag/v8.18.3