← Vulnerability feed

Vulnerability record · CVE-2026-33327 · published 20 July 2026

CVE-2026-33327: Libvips integer overflow vulnerability

Libvips · Libvips

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.

7.0 CVSS 4.0 High EPSS 0.18% · top 93.3% CWE-190 · Integer overflow
7.0CVSS 4.0 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
19 Aug 2026Last modified by NVD

Description

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33327 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-17534Libvips use after free vulnerabilityvips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, leading to …EPSS 2.4%8.5CVE-2025-29769Libvips heap-based buffer overflow vulnerabilitylibvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alp…EPSS 0.28%7.5CVE-2018-7998Libvips race condition vulnerabilityIn libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows r…EPSS 1.8%7.0CVE-2026-35591Libvips heap-based buffer overflow vulnerabilitylibvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could inco…EPSS 0.18%6.8CVE-2026-35590Libvips heap-based buffer overflow vulnerabilitylibvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verify…EPSS 0.15%6.8CVE-2026-33328Libvips integer overflow vulnerabilitylibvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation …EPSS 0.15%6.5CVE-2021-27847Libvips divide by zero vulnerabilityDivision-By-Zero vulnerability in Libvips 8.10.5 in the function vips_eye_point, eye.c#L83, and function vips_mask_point, mask.c#L85.EPSS 0.98%5.5CVE-2023-40032Fedoraproject fedora null pointer dereference vulnerabilitylibvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlie…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2026-33327), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.