CVE-2026-35590
MEDIUMPossible out-of-bounds read leading to crash when decoding well-crafted EXIF metadata
Title source: cnaDescription
libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/libvips/libvips/security/advisories/GHSA-jmwm-wc68-mhwm
X_Refsource_Misc x_refsource_misc
https://github.com/libvips/libvips/pull/4972
X_Refsource_Misc x_refsource_misc
https://github.com/libvips/libvips/commit/91ebd4d35341a8353ea490392d556d582e4b846f
Scores
CVSS v4
6.8
EPSS
0.0012
EPSS Percentile
2.1%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-122
Status
published
Products (1)
libvips/libvips
<= 8.18.1
Published
Jul 20, 2026
Tracked Since
Jul 20, 2026