๐Ÿ” CVE Alert

CVE-2026-70654

UNKNOWN 0.0

libvips: A well-crafted PPM image processed via a custom source could lead to possible heap buffer write overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in libvips/iofuncs/source.c. The function uses VIPS_MAX instead of VIPS_MIN when selecting the remaining read size, allowing up to 4032 bytes to be written beyond the allocated heap buffer and causing memory corruption or a process crash. This issue is fixed in version 8.18.3.

CWE CWE-122
Vendor libvips
Product libvips
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for libvips libvips

Be the first to know when new unknown vulnerabilities affecting libvips libvips are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

libvips / libvips
< 8.18.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/libvips/libvips/security/advisories/GHSA-rjmm-3qch-m9rg github.com: https://github.com/libvips/libvips/pull/5038 github.com: https://github.com/libvips/libvips/commit/80e021c6cdda0f80b756c2109d99839c94c03258 github.com: https://github.com/libvips/libvips/releases/tag/v8.18.3