CVE-2026-35590

MEDIUM

Possible out-of-bounds read leading to crash when decoding well-crafted EXIF metadata

Title source: cna
STIX 2.1

Description

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.

Scores

CVSS v4 6.8
EPSS 0.0012
EPSS Percentile 2.1%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-122
Status published
Products (1)
libvips/libvips <= 8.18.1
Published Jul 20, 2026
Tracked Since Jul 20, 2026