{"schema_version":1,"title":"Libvips vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in Libvips: 1 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88360, was published on 24 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/libvips","json_url":"https://junglewise.ai/threats/vendors/libvips.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/libvips","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":1,"all_time":12,"critical":0,"exploited":0,"last_7_days":1,"last_30_days":1,"last_90_days":12,"last_365_days":12},"latest":[{"cve":"CVE-2026-88360","epss":0.0014,"slug":"cve-2026-88360-libvips-8-19-0-contains-a-memory-access-vulnerability-when","title":"libvips misaligned float load in PFM image processing","severity":"info","exploited":false,"published_at":"2026-09-24T14:18:18.44+00:00","url":"https://junglewise.ai/threats/cve-2026-88360-libvips-8-19-0-contains-a-memory-access-vulnerability-when"},{"cve":"CVE-2026-70654","cvss":8.6,"epss":0.0014,"slug":"cve-2026-70654-libvips-heap-buffer-overflow-in-ppm-source-processing","title":"libvips heap buffer overflow in PPM source processing","severity":"info","exploited":false,"published_at":"2026-08-20T21:17:08.567+00:00","url":"https://junglewise.ai/threats/cve-2026-70654-libvips-heap-buffer-overflow-in-ppm-source-processing"},{"cve":"CVE-2026-70653","epss":0.0016,"slug":"cve-2026-70653-libvips-radiance-rle-decoder-heap-disclosure","title":"libvips Radiance RLE decoder heap disclosure","severity":"info","exploited":false,"published_at":"2026-08-20T21:17:08.427+00:00","url":"https://junglewise.ai/threats/cve-2026-70653-libvips-radiance-rle-decoder-heap-disclosure"},{"cve":"CVE-2026-70652","epss":0.0014,"slug":"cve-2026-70652-libvips-heap-buffer-over-read-in-uhdr-save","title":"libvips heap buffer over-read in UHDR save","severity":"info","exploited":false,"published_at":"2026-08-20T21:17:08.27+00:00","url":"https://junglewise.ai/threats/cve-2026-70652-libvips-heap-buffer-over-read-in-uhdr-save"},{"cve":"CVE-2026-70651","epss":0.0016,"slug":"cve-2026-70651-libvips-heap-buffer-over-read-in-imagemagick-fallback-path","title":"libvips heap buffer over-read in ImageMagick fallback path","severity":"info","exploited":false,"published_at":"2026-08-20T21:17:08.12+00:00","url":"https://junglewise.ai/threats/cve-2026-70651-libvips-heap-buffer-over-read-in-imagemagick-fallback-path"},{"cve":"CVE-2026-69242","epss":0.0027,"slug":"cve-2026-69242-libvips-integer-overflow-in-tiff-scanline-processing","title":"libvips integer overflow in TIFF scanline processing","severity":"info","exploited":false,"published_at":"2026-08-20T21:17:07.697+00:00","url":"https://junglewise.ai/threats/cve-2026-69242-libvips-integer-overflow-in-tiff-scanline-processing"},{"cvss":4,"slug":"sharp-inherited-vulnerabilities-in-libvips-7540ca3a","title":"sharp inherited vulnerabilities in libvips","severity":"medium","exploited":false,"published_at":"2026-07-21T22:07:17+00:00","url":"https://junglewise.ai/threats/sharp-inherited-vulnerabilities-in-libvips-7540ca3a"},{"cvss":7,"slug":"lovell-sharp-inherited-buffer-overflows-in-libvips-7c2b2996","title":"lovell sharp inherited buffer overflows in libvips","severity":"high","exploited":false,"published_at":"2026-07-21T22:07:17+00:00","url":"https://junglewise.ai/threats/lovell-sharp-inherited-buffer-overflows-in-libvips-7c2b2996"},{"cve":"CVE-2026-35591","cvss":7,"slug":"cve-2026-35591-libvips-heap-buffer-overflow-in-tiffload","title":"libvips heap buffer overflow in tiffload","severity":"info","exploited":false,"published_at":"2026-07-20T17:17:07.277+00:00","url":"https://junglewise.ai/threats/cve-2026-35591-libvips-heap-buffer-overflow-in-tiffload"},{"cve":"CVE-2026-35590","cvss":6.8,"slug":"cve-2026-35590-libvips-null-pointer-dereference-in-exif-decoder","title":"libvips null pointer dereference in EXIF decoder","severity":"info","exploited":false,"published_at":"2026-07-20T17:17:07.133+00:00","url":"https://junglewise.ai/threats/cve-2026-35590-libvips-null-pointer-dereference-in-exif-decoder"},{"cve":"CVE-2026-33328","cvss":6.8,"slug":"cve-2026-33328-libvips-integer-overflow-in-gifload-on-32-bit-systems","title":"libvips integer overflow in gifload on 32-bit systems","severity":"info","exploited":false,"published_at":"2026-07-20T17:17:06.43+00:00","url":"https://junglewise.ai/threats/cve-2026-33328-libvips-integer-overflow-in-gifload-on-32-bit-systems"},{"cve":"CVE-2026-33327","cvss":7,"slug":"cve-2026-33327-libvips-heap-buffer-overflow-in-vipsload-operation","title":"libvips heap buffer overflow in vipsload operation","severity":"info","exploited":false,"published_at":"2026-07-20T17:17:06.283+00:00","url":"https://junglewise.ai/threats/cve-2026-33327-libvips-heap-buffer-overflow-in-vipsload-operation"}],"vendor":{"hub":true,"name":"Libvips","slug":"libvips","homepage":"https://www.libvips.org/","description":"libvips is an open-source image processing library designed to handle large images efficiently with low memory usage.","url":"https://junglewise.ai/threats/vendors/libvips"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cvss":7,"slug":"lovell-sharp-inherited-buffer-overflows-in-libvips-7c2b2996","title":"lovell sharp inherited buffer overflows in libvips","severity":"high","exploited":false,"published_at":"2026-07-21T22:07:17+00:00","url":"https://junglewise.ai/threats/lovell-sharp-inherited-buffer-overflows-in-libvips-7c2b2996"},{"cvss":4,"slug":"sharp-inherited-vulnerabilities-in-libvips-7540ca3a","title":"sharp inherited vulnerabilities in libvips","severity":"medium","exploited":false,"published_at":"2026-07-21T22:07:17+00:00","url":"https://junglewise.ai/threats/sharp-inherited-vulnerabilities-in-libvips-7540ca3a"},{"cve":"CVE-2026-70654","cvss":8.6,"epss":0.0014,"slug":"cve-2026-70654-libvips-heap-buffer-overflow-in-ppm-source-processing","title":"libvips heap buffer overflow in PPM source processing","severity":"info","exploited":false,"published_at":"2026-08-20T21:17:08.567+00:00","url":"https://junglewise.ai/threats/cve-2026-70654-libvips-heap-buffer-overflow-in-ppm-source-processing"},{"cve":"CVE-2026-35591","cvss":7,"slug":"cve-2026-35591-libvips-heap-buffer-overflow-in-tiffload","title":"libvips heap buffer overflow in tiffload","severity":"info","exploited":false,"published_at":"2026-07-20T17:17:07.277+00:00","url":"https://junglewise.ai/threats/cve-2026-35591-libvips-heap-buffer-overflow-in-tiffload"},{"cve":"CVE-2026-33327","cvss":7,"slug":"cve-2026-33327-libvips-heap-buffer-overflow-in-vipsload-operation","title":"libvips heap buffer overflow in vipsload operation","severity":"info","exploited":false,"published_at":"2026-07-20T17:17:06.283+00:00","url":"https://junglewise.ai/threats/cve-2026-33327-libvips-heap-buffer-overflow-in-vipsload-operation"},{"cve":"CVE-2026-35590","cvss":6.8,"slug":"cve-2026-35590-libvips-null-pointer-dereference-in-exif-decoder","title":"libvips null pointer dereference in EXIF decoder","severity":"info","exploited":false,"published_at":"2026-07-20T17:17:07.133+00:00","url":"https://junglewise.ai/threats/cve-2026-35590-libvips-null-pointer-dereference-in-exif-decoder"},{"cve":"CVE-2026-33328","cvss":6.8,"slug":"cve-2026-33328-libvips-integer-overflow-in-gifload-on-32-bit-systems","title":"libvips integer overflow in gifload on 32-bit systems","severity":"info","exploited":false,"published_at":"2026-07-20T17:17:06.43+00:00","url":"https://junglewise.ai/threats/cve-2026-33328-libvips-integer-overflow-in-gifload-on-32-bit-systems"},{"cve":"CVE-2026-69242","epss":0.0027,"slug":"cve-2026-69242-libvips-integer-overflow-in-tiff-scanline-processing","title":"libvips integer overflow in TIFF scanline processing","severity":"info","exploited":false,"published_at":"2026-08-20T21:17:07.697+00:00","url":"https://junglewise.ai/threats/cve-2026-69242-libvips-integer-overflow-in-tiff-scanline-processing"},{"cve":"CVE-2026-70653","epss":0.0016,"slug":"cve-2026-70653-libvips-radiance-rle-decoder-heap-disclosure","title":"libvips Radiance RLE decoder heap disclosure","severity":"info","exploited":false,"published_at":"2026-08-20T21:17:08.427+00:00","url":"https://junglewise.ai/threats/cve-2026-70653-libvips-radiance-rle-decoder-heap-disclosure"},{"cve":"CVE-2026-70651","epss":0.0016,"slug":"cve-2026-70651-libvips-heap-buffer-over-read-in-imagemagick-fallback-path","title":"libvips heap buffer over-read in ImageMagick fallback path","severity":"info","exploited":false,"published_at":"2026-08-20T21:17:08.12+00:00","url":"https://junglewise.ai/threats/cve-2026-70651-libvips-heap-buffer-over-read-in-imagemagick-fallback-path"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Libvips","slug":"libvips","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/libvips"}]}