These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in libvips/iofuncs/source.c. This error allows up to 4032 bytes to be written beyond the allocated heap buffer, causing memory corruption or a pr [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T21:17:08.270Z and has not been modified since then. The vulnerability affects libvips, a fast image processing library with low memory needs, specifically when built with libultrahdr support. An undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the p [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T21:17:07.697Z and has not been modified since then. The NVD entry is currently 8.4 HIGH. libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image [truncated]
The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2. The vulnerability affects users of the libvips library, especially those processing TIFF images with JPEG or JPEG2000-encoded tiles. An executive ov [truncated]
The CVE record for CVE-2026-35590 was published on 2026-07-20T17:17:07.133Z and has not been modified since then. The NVD entry is currently 6.8 MEDIUM. libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer derefe [truncated]
CVE-2026-33328 is an integer overflow vulnerability in libvips 8.18.0 and earlier on 32-bit systems. The `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1. Affected product deployments on 32-bit systems require review, and owners should be assigned for follow-up. Official advisories and CVE records should be reviewed to valid [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T17:17:06.283Z and has not been modified since then. The `vipsload` operation in libvips versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1. Users of l [truncated]