CVE-2026-3147

MEDIUM

libvips <=8.18.0 - Buffer Overflow

Title source: llm

Description

A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been made public and could be used. The patch is identified as b3ab458a25e0e261cbd1788474bbc763f7435780. It is advisable to implement a patch to correct this issue.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 4.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-119 CWE-122
Status published

Affected Products (1)

libvips/libvips < 8.18.0

Timeline

Published Feb 25, 2026
Tracked Since Feb 25, 2026