CVE-2026-35591

Source
https://cve.org/CVERecord?id=CVE-2026-35591
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35591.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-35591
Aliases
  • GHSA-523x-vhfw-6r76
Downstream
Published
2026-07-20T16:24:50.831Z
Modified
2026-08-12T16:23:52.724141Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile
Details

libvips is a fast image processing library with low memory needs. The tiffload operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35591.json"
}
References

Affected packages

Git / github.com/libvips/libvips

Affected ranges

Type
GIT
Repo
https://github.com/libvips/libvips
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.18.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v7.*
v7.28.0
v8.*
v8.0-beta
v8.1
v8.10.0
v8.10.0-beta1
v8.10.0-beta2
v8.10.0-rc1
v8.10.0-rc2
v8.10.6-beta2
v8.11
v8.11.0
v8.11.0-rc1
v8.12.0
v8.12.0-rc1
v8.13.0
v8.13.0-pre1
v8.13.0-rc1
v8.13.0-rc2
v8.14.0
v8.14.0-rc1
v8.15.0
v8.15.0-rc2
v8.16.0
v8.16.0-rc1
v8.16.0-rc2
v8.17.0
v8.17.0-rc1
v8.17.0-test1
v8.17.0-test2
v8.17.0-test3
v8.17.0-test4
v8.18.0
v8.18.0-alpha1
v8.18.0-alpha2
v8.18.0-rc1
v8.18.0-rc2
v8.18.0-rc3
v8.18.1
v8.2.2
v8.3.0
v8.5.1
v8.5.2
v8.5.3
v8.6.0
v8.6.0-alpha1
v8.6.0-alpha2
v8.6.0-beta1
v8.6.0-beta2
v8.7.0
v8.7.0-alpha2
v8.7.0-rc1
v8.7.0-rc2
v8.7.0-rc3
v8.8.0
v8.8.0-rc1
v8.8.0-rc2
v8.8.0-rc3
v8.9.0
v8.9.0-alpha1
v8.9.0-beta1
v8.9.0-beta2
v8.9.0-rc1
v8.9.0-rc2
v8.9.0-rc3
v8.9.0-rc4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35591.json"
vanir_signatures
[
    {
        "target": {
            "file": "libvips/foreign/tiff2vips.c"
        },
        "deprecated": false,
        "source": "https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe",
        "id": "CVE-2026-35591-0efcb857",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "334446943446665342501250574526145812539",
                "266639340064547046276747042074508342896",
                "12071334408861425980460823472380151471",
                "142506264369531565533195822746451527500"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "vips_foreign_load_jp2k_header",
            "file": "libvips/foreign/jp2kload.c"
        },
        "deprecated": false,
        "source": "https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe",
        "id": "CVE-2026-35591-100ceba4",
        "signature_version": "v1",
        "digest": {
            "length": 1379.0,
            "function_hash": "19891091081394832987051736408313798275"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "vips_foreign_load_jp2k_generate_untiled",
            "file": "libvips/foreign/jp2kload.c"
        },
        "deprecated": false,
        "source": "https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe",
        "id": "CVE-2026-35591-31198739",
        "signature_version": "v1",
        "digest": {
            "length": 1580.0,
            "function_hash": "314795997488036864468850035574195345744"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "libvips/foreign/jp2kload.c"
        },
        "deprecated": false,
        "source": "https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe",
        "id": "CVE-2026-35591-6f474f6d",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "226799909877807659285490770275639837796",
                "262319790991739063364279623433161153928",
                "74581169411709225073090025262717930354",
                "664867752229300434178153250094377039",
                "220166180862611395656168537984515288348",
                "190559348327466607830251463642080103084",
                "36166306246568003215501536439623036800",
                "260458028198078392132216653541170342673",
                "327740737921250843757776675491527687882",
                "19318788253601659059027498180181400539",
                "20982242232628166514688029097576168213",
                "222613788378665974984707375594297806837",
                "11991112549517534563528635106582658963",
                "91096039064502450264305662829384932096",
                "218640961339796131559535252972743599182",
                "173880245933184051894152545564130220546",
                "7308911191249598365786543875285117906",
                "209253474040954115970794107289818101859",
                "35551642934319494006734460242576762786",
                "301498188223892945096981820007306153854",
                "99606358875984692459733966296514913648",
                "160302061576617993718488937012743287135",
                "12462434668086025598119242186195946946",
                "307266903725538188392143452036242870349",
                "162289245472186640488504227465691293655",
                "286296970952603245069765485750694385411",
                "66650176159536853900465156155505256698",
                "213881475579775202930925555780269184257",
                "42775758973717697137286361274301416410",
                "325646444715410066844947238010803221687",
                "217429509776702288324962444975093948025",
                "99910992131710471681879593996092630401",
                "168729663854147352829288477888939428857",
                "95942673609488616040507548799857288362",
                "217429509776702288324962444975093948025",
                "99910992131710471681879593996092630401",
                "238485074102862404181517164462591736239",
                "72687738435764000573608477025591424944",
                "244450576278680018267515271633531514190",
                "311378769205653024404310822312885158656",
                "270199727046986186524237466536745643270"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "vips_foreign_load_jp2k_check_supported",
            "file": "libvips/foreign/jp2kload.c"
        },
        "deprecated": false,
        "source": "https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe",
        "id": "CVE-2026-35591-8eeccdcb",
        "signature_version": "v1",
        "digest": {
            "length": 1001.0,
            "function_hash": "298273362866700007392165939252667409108"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "vips_foreign_load_jp2k_generate_tiled",
            "file": "libvips/foreign/jp2kload.c"
        },
        "deprecated": false,
        "source": "https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe",
        "id": "CVE-2026-35591-c5d51fa9",
        "signature_version": "v1",
        "digest": {
            "length": 1975.0,
            "function_hash": "8313486697761689144862972010519137560"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "vips__foreign_load_jp2k_decompress",
            "file": "libvips/foreign/jp2kload.c"
        },
        "deprecated": false,
        "source": "https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe",
        "id": "CVE-2026-35591-f6ebc548",
        "signature_version": "v1",
        "digest": {
            "length": 1660.0,
            "function_hash": "93849039275936212560091913181534957033"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "rtiff_decompress_jpeg_run",
            "file": "libvips/foreign/tiff2vips.c"
        },
        "deprecated": false,
        "source": "https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe",
        "id": "CVE-2026-35591-fb84885e",
        "signature_version": "v1",
        "digest": {
            "length": 1617.0,
            "function_hash": "140533827483987169618465145593423126993"
        },
        "signature_type": "Function"
    }
]
vanir_signatures_modified
"2026-08-12T16:23:52Z"