CVE-2026-35591: Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile
Published Jul 20, 2026
·Updated
libvips is a fast image processing library with low memory needs. The tiffload operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.
Affected Software
2 affected components
libvips libvips<=8.18.1
libvips libvips<8.18.2
Remediation
Patch Available
Event History
Jul 20, 2026
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35591?
CVE-2026-35591 has a high severity rating of 7.
2
How can I fix CVE-2026-35591?
To fix CVE-2026-35591, upgrade libvips to version 8.18.2 or later.
3
What is the risk associated with CVE-2026-35591?
The risk associated with CVE-2026-35591 is rated at 61, indicating a significant potential impact.
4
What types of images are affected by CVE-2026-35591?
CVE-2026-35591 affects TIFF images that contain JPEG or JPEG2000-encoded tiles.
5
What exploit does CVE-2026-35591 pose?
CVE-2026-35591 poses a potential buffer overflow vulnerability when processing certain TIFF images.