The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2. The vulnerability affects users of the libvips library, especially those processing TIFF images with JPEG or JPEG2000-encoded tiles. An executive ov [truncated]
The CVE record for CVE-2026-35590 was published on 2026-07-20T17:17:07.133Z and has not been modified since then. The NVD entry is currently 6.8 MEDIUM. libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer derefe [truncated]
CVE-2026-33328 is an integer overflow vulnerability in libvips 8.18.0 and earlier on 32-bit systems. The `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1. Affected product deployments on 32-bit systems require review, and owners should be assigned for follow-up. Official advisories and CVE records should be reviewed to valid [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T17:17:06.283Z and has not been modified since then. The `vipsload` operation in libvips versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1. Users of l [truncated]