{"id":"CVE-2026-3147","summary":"libvips csvload.c vips_foreign_load_csv_build heap-based overflow","details":"A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been made public and could be used. The patch is identified as b3ab458a25e0e261cbd1788474bbc763f7435780. It is advisable to implement a patch to correct this issue.","modified":"2026-07-17T21:09:17.356265776Z","published":"2026-02-25T03:32:09.025Z","database_specific":{"cwe_ids":["CWE-119","CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3147.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"8.2"},{"last_affected":"8.2"},{"introduced":"8.4"},{"last_affected":"8.4"},{"introduced":"8.5"},{"last_affected":"8.5"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/libvips/libvips/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3147.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3147"},{"type":"ADVISORY","url":"https://vuldb.com/?id.347653"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.758692"},{"type":"REPORT","url":"https://github.com/libvips/libvips/issues/4874"},{"type":"REPORT","url":"https://github.com/libvips/libvips/issues/4874#issue-3943617697"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.347653"},{"type":"FIX","url":"https://github.com/libvips/libvips/commit/b3ab458a25e0e261cbd1788474bbc763f7435780"},{"type":"FIX","url":"https://github.com/libvips/libvips/pull/4894"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libvips/libvips","events":[{"introduced":"0"},{"fixed":"b3ab458a25e0e261cbd1788474bbc763f7435780"}],"database_specific":{"cpe":"cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"8.18.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["8.1","8.10","8.11","8.12","8.13","8.14","8.15","8.16","8.17","8.18.0","8.3","8.6","8.7","8.8","8.9","v8.18.0","v8.18.0-rc3","v8.18.0-rc2","v8.18.0-rc1","v8.18.0-alpha2","v8.18.0-alpha1","v8.17.0-rc1","v8.17.0","v8.17.0-test4","v8.17.0-test3","v8.17.0-test2","v8.17.0-test1","v8.16.0","v8.16.0-rc2","v8.16.0-rc1","v8.15.0","v8.15.0-rc2","v8.14.0","v8.14.0-rc1","v8.13.0","v8.13.0-rc2","v8.13.0-rc1","v8.13.0-pre1","v8.12.0","v8.12.0-rc1","v8.11.0","v8.11","v8.11.0-rc1","v8.10.6-beta2","v8.10.0","v8.10.0-rc2","v8.10.0-rc1","v8.10.0-beta2","v8.10.0-beta1","v8.9.0","v8.9.0-rc4","v8.9.0-rc3","v8.9.0-rc2","v8.9.0-rc1","v8.9.0-beta2","v8.9.0-beta1","v8.9.0-alpha1","v8.8.0-rc3","v8.8.0","v8.8.0-rc2","v8.8.0-rc1","v8.7.0","v8.7.0-rc3","v8.7.0-rc2","v8.7.0-rc1","v8.7.0-alpha2","v8.6.0","v8.6.0-beta2","v8.6.0-beta1","v8.6.0-alpha2","v8.6.0-alpha1","v8.5.3","v8.5.2","v8.5.1","v8.3.0","v8.2.2","v8.1","v8.0-beta","v7.28.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-3147.json","vanir_signatures_modified":"2026-07-15T00:14:09Z","vanir_signatures":[{"deprecated":false,"digest":{"length":610,"function_hash":"94416421560491218846403034441503477891"},"id":"CVE-2026-3147-5591ae0b","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/b3ab458a25e0e261cbd1788474bbc763f7435780","target":{"file":"libvips/foreign/csvload.c","function":"vips_foreign_load_csv_build"}},{"digest":{"line_hashes":["122335264043279036409568682435354209833","249420623776449755065113853178165918255","261020416832808719966525272977935915183"],"threshold":0.9},"id":"CVE-2026-3147-af928aef","signature_type":"Line","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/b3ab458a25e0e261cbd1788474bbc763f7435780","target":{"file":"libvips/foreign/csvload.c"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}