๐Ÿ” CVE Alert

CVE-2026-70652

UNKNOWN 0.0

libvips: Possible heap-based buffer read overflow when resizing and re-encoding a JPEG with gain map

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.

CWE CWE-126
Vendor libvips
Product libvips
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for libvips libvips

Be the first to know when new unknown vulnerabilities affecting libvips libvips are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

libvips / libvips
< 8.18.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/libvips/libvips/security/advisories/GHSA-h27h-jf9v-m8rg github.com: https://github.com/libvips/libvips/pull/5039 github.com: https://github.com/libvips/libvips/commit/cff17794f0698a4f47c74bb31c9700b2c83252a8 github.com: https://github.com/libvips/libvips/releases/tag/v8.18.3