CVE-2026-33327

Source
https://cve.org/CVERecord?id=CVE-2026-33327
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33327.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-33327
Aliases
  • GHSA-2fcj-gj27-279x
Downstream
Published
2026-07-20T16:21:16.663Z
Modified
2026-08-07T21:13:30.595459Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Possible integer overflow leading to potential heap-based buffer overflow
Details

libvips is a fast image processing library with low memory needs. The vipsload operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.

Database specific
{
    "cwe_ids": [
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33327.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/libvips/libvips

Affected ranges

Type
GIT
Repo
https://github.com/libvips/libvips
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.18.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v7.*
v7.28.0
v8.*
v8.0-beta
v8.1
v8.10.0
v8.10.0-beta1
v8.10.0-beta2
v8.10.0-rc1
v8.10.0-rc2
v8.10.6-beta2
v8.11
v8.11.0
v8.11.0-rc1
v8.12.0
v8.12.0-rc1
v8.13.0
v8.13.0-pre1
v8.13.0-rc1
v8.13.0-rc2
v8.14.0
v8.14.0-rc1
v8.15.0
v8.15.0-rc2
v8.16.0
v8.16.0-rc1
v8.16.0-rc2
v8.17.0
v8.17.0-rc1
v8.17.0-test1
v8.17.0-test2
v8.17.0-test3
v8.17.0-test4
v8.18.0
v8.18.0-alpha1
v8.18.0-alpha2
v8.18.0-rc1
v8.18.0-rc2
v8.18.0-rc3
v8.2.2
v8.3.0
v8.5.1
v8.5.2
v8.5.3
v8.6.0
v8.6.0-alpha1
v8.6.0-alpha2
v8.6.0-beta1
v8.6.0-beta2
v8.7.0
v8.7.0-alpha2
v8.7.0-rc1
v8.7.0-rc2
v8.7.0-rc3
v8.8.0
v8.8.0-rc1
v8.8.0-rc2
v8.8.0-rc3
v8.9.0
v8.9.0-alpha1
v8.9.0-beta1
v8.9.0-beta2
v8.9.0-rc1
v8.9.0-rc2
v8.9.0-rc3
v8.9.0-rc4

Database specific

vanir_signatures_modified
"2026-08-07T21:13:30Z"
vanir_signatures
[
    {
        "id": "CVE-2026-33327-003d39ad",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 472.0,
            "function_hash": "143388755829374086000473818095288249890"
        },
        "source": "https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9",
        "target": {
            "function": "vips_object_real_build",
            "file": "libvips/iofuncs/object.c"
        }
    },
    {
        "id": "CVE-2026-33327-0db3dd71",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "223480178086453787758278101131898914023",
                "234109384368306172353704833698790472522",
                "203026080740743270553777003150943660021",
                "248141106496541395162563418364402220617",
                "339954748138605696925252810262295272885",
                "13772120599242725202695205406644807555",
                "290945251364916201926030577727999565048",
                "28952029360003528383911986693415495998",
                "94852133193140340522014995263817466447",
                "156307606320818711184458339415991190381",
                "68258179252485364908224457038677793119",
                "154924044923671274225407175476418747120",
                "256469169406346963090255168939248706891",
                "199487052798995775728366738072546101363",
                "42367196625450845047475095465279850500",
                "97046239578848936430317252861049987165",
                "86209948823509730988730590290245118086",
                "98111944504458370823792203190881803758",
                "328604566234503360421637311794720751543",
                "339281787114015736839789416465932456995",
                "268292218123558155747608856266121054333",
                "161650081762172514091200439668273605261",
                "333402744843380120209399108178115064391",
                "64918344687275377627097621748918497969",
                "327283146037136802408874656781483404698",
                "132248055333387100583677680915338084821",
                "107577196072034127947986122354418583262",
                "130127050308482253665868908424856385939",
                "202046648355123045680049567066756720534",
                "178791434624156141083113354471032309882",
                "168930484512929450955871164240090586730",
                "313314112781150994923980219013402316303",
                "221314034702355828632611677649467611242"
            ]
        },
        "source": "https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9",
        "target": {
            "file": "libvips/iofuncs/image.c"
        }
    },
    {
        "id": "CVE-2026-33327-613a13bc",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 877.0,
            "function_hash": "235409723021130373820335314141619391437"
        },
        "source": "https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9",
        "target": {
            "function": "vips_image_write_prepare",
            "file": "libvips/iofuncs/image.c"
        }
    },
    {
        "id": "CVE-2026-33327-70a3b6fe",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 1078.0,
            "function_hash": "181643012072986684283103543519486481630"
        },
        "source": "https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9",
        "target": {
            "function": "vips_image_sanity",
            "file": "libvips/iofuncs/image.c"
        }
    },
    {
        "id": "CVE-2026-33327-942ebc33",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "55799577680472821362884523340459635882",
                "283637038327270297070660887698697026321",
                "171139218678004698631355228866167495725"
            ]
        },
        "source": "https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9",
        "target": {
            "file": "libvips/iofuncs/object.c"
        }
    },
    {
        "id": "CVE-2026-33327-d928ead3",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 729.0,
            "function_hash": "19156182895307988900939440773607157352"
        },
        "source": "https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9",
        "target": {
            "function": "vips_image_new_from_memory",
            "file": "libvips/iofuncs/image.c"
        }
    },
    {
        "id": "CVE-2026-33327-e960ee89",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 2735.0,
            "function_hash": "197515869315236039657997456147584749601"
        },
        "source": "https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9",
        "target": {
            "function": "vips_image_build",
            "file": "libvips/iofuncs/image.c"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33327.json"