Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

libvips — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in libvips, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the libvips image processing library. It aggregates security vulnerabilities identified in this specific software product, providing a centralized view of its exposure to various weakness classes. The content covers known issues reported within the last three years, ensuring that users have access to recent and relevant security data while maintaining historical context for older findings. This aggregation serves as a resource for security analysts, developers, and system administrators who need to understand the threat landscape surrounding libvips. Users can track vendor advisories related to this library to stay informed about official patch releases and mitigation strategies. The page also allows for a deeper understanding of specific weakness classes affecting the product, such as buffer overflows or injection flaws, by categorizing entries according to established vulnerability typologies. Furthermore, it enables the lookup of a product’s vulnerability history, offering a chronological perspective on how security issues have evolved within the libvips codebase over time. By consolidating this information, the page facilitates proactive risk management and helps organizations prioritize remediation efforts based on the severity and prevalence of reported weaknesses. This structured approach supports better decision-making for maintaining secure environments that rely on the libvips library for high-performance image manipulation tasks.

Vendor: libvips

CVE IDTitleCVSSSeverityPublished
CVE-2026-35591 Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile CWE-122--2026-07-20
CVE-2026-35590 Possible out-of-bounds read leading to crash when decoding well-crafted EXIF metadata CWE-122--2026-07-20
CVE-2026-33328 Possible integer overflow on 32-bit systems when reading GIF images CWE-190--2026-07-20
CVE-2026-33327 Possible integer overflow leading to potential heap-based buffer overflow CWE-190--2026-07-20
CVE-2026-6491 libvips nip2 vips7compat.c im_minpos_vec heap-based overflow CWE-122 5.3 Medium2026-04-17
CVE-2026-3284 libvips extract.c vips_extract_area_build integer overflow CWE-190 3.3 Low2026-02-27
CVE-2026-3283 libvips extract.c vips_extract_band_build out-of-bounds CWE-125 3.3 Low2026-02-27
CVE-2026-3282 libvips unpremultiply.c vips_unpremultiply_build out-of-bounds CWE-125 3.3 Low2026-02-27
CVE-2026-3281 libvips bandrank.c vips_bandrank_build heap-based overflow CWE-122 5.3 Medium2026-02-27
CVE-2026-3147 libvips csvload.c vips_foreign_load_csv_build heap-based overflow CWE-122 5.3 Medium2026-02-25
CVE-2026-3146 libvips matrixload.c vips_foreign_load_matrix_header null pointer dereference CWE-476 3.3 Low2026-02-25
CVE-2026-3145 libvips matrixload.c vips_foreign_load_matrix_header memory corruption CWE-119 5.3 Medium2026-02-25
CVE-2026-2913 libvips source.c vips_source_read_to_memory heap-based overflow CWE-122 2.5 Low2026-02-22
CVE-2025-59933 libvips is vulnerable to Buffer Over-Read in poppler-based pdfload CWE-126 8.8AIHighAI2025-09-29
CVE-2025-29769 libvips has a potential heap-based buffer overflow when attempting to convert multiband TIFF input to HEIF output CWE-122 5.5AIMediumAI2025-04-07
CVE-2023-40032 Potential segfault due to NULL pointer dereference in libvips CWE-476 5.5 Medium2023-09-11

All 16 known CVE vulnerabilities affecting libvips with full Chinese analysis, references, and POCs where available.