CVE-2026-70651: Libvips

Medium severity, CVSS 6.9. EPSS: 0.2% chance of exploitation in the next 30 days.

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3.

Affected products

  • Libvips Libvips: before 8.18.3 (fixed in 8.18.3)

Published 2026-08-20. Last modified 2026-09-18.