CVE-2026-70653: Libvips
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1] before any prior pixel exists. A crafted Radiance image loaded through VipsForeignLoadRad can therefore disclose four bytes of adjacent heap data, most likely other image data. This issue is fixed in version 8.18.3.
Affected products
- Libvips Libvips: before 8.18.3 (fixed in 8.18.3)
Published 2026-08-20. Last modified 2026-09-18.