{"id":"CVE-2026-35591","summary":"Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile","details":"libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.","aliases":["GHSA-523x-vhfw-6r76"],"modified":"2026-08-21T09:09:33.753712Z","published":"2026-07-20T16:24:50.831Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35591.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35591.json"},{"type":"ADVISORY","url":"https://github.com/libvips/libvips/security/advisories/GHSA-523x-vhfw-6r76"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35591"},{"type":"FIX","url":"https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe"},{"type":"FIX","url":"https://github.com/libvips/libvips/pull/4973"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libvips/libvips","events":[{"introduced":"0"},{"fixed":"17ad2f62dda7e39985955da189183e594683d45e"},{"fixed":"df044e409a0db77c980fa1a9f86a13fbfb2dc8fe"}],"database_specific":{"cpe":"cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"8.18.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v8.18.1","v8.18.0","v8.18.0-rc3","v8.18.0-rc2","v8.18.0-rc1","v8.18.0-alpha2","v8.18.0-alpha1","v8.17.0-rc1","v8.17.0","v8.17.0-test4","v8.17.0-test3","v8.17.0-test2","v8.17.0-test1","v8.16.0","v8.16.0-rc2","v8.16.0-rc1","v8.15.0","v8.15.0-rc2","v8.14.0","v8.14.0-rc1","v8.13.0","v8.13.0-rc2","v8.13.0-rc1","v8.13.0-pre1","v8.12.0","v8.12.0-rc1","v8.11.0","v8.11","v8.11.0-rc1","v8.10.6-beta2","v8.10.0","v8.10.0-rc2","v8.10.0-rc1","v8.10.0-beta2","v8.10.0-beta1","v8.9.0","v8.9.0-rc4","v8.9.0-rc3","v8.9.0-rc2","v8.9.0-rc1","v8.9.0-beta2","v8.9.0-beta1","v8.9.0-alpha1","v8.8.0-rc3","v8.8.0","v8.8.0-rc2","v8.8.0-rc1","v8.7.0","v8.7.0-rc3","v8.7.0-rc2","v8.7.0-rc1","v8.7.0-alpha2","v8.6.0","v8.6.0-beta2","v8.6.0-beta1","v8.6.0-alpha2","v8.6.0-alpha1","v8.5.3","v8.5.2","v8.5.1","v8.3.0","v8.2.2","v8.1","v8.0-beta","v7.28.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-35591.json","vanir_signatures_modified":"2026-08-21T09:09:33Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["334446943446665342501250574526145812539","266639340064547046276747042074508342896","12071334408861425980460823472380151471","142506264369531565533195822746451527500"],"threshold":0.9},"id":"CVE-2026-35591-0efcb857","signature_type":"Line","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe","target":{"file":"libvips/foreign/tiff2vips.c"}},{"source":"https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe","target":{"function":"vips_foreign_load_jp2k_header","file":"libvips/foreign/jp2kload.c"},"deprecated":false,"digest":{"function_hash":"19891091081394832987051736408313798275","length":1379},"id":"CVE-2026-35591-100ceba4","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"314795997488036864468850035574195345744","length":1580},"id":"CVE-2026-35591-31198739","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe","target":{"function":"vips_foreign_load_jp2k_generate_untiled","file":"libvips/foreign/jp2kload.c"}},{"source":"https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe","target":{"file":"libvips/foreign/jp2kload.c"},"deprecated":false,"digest":{"line_hashes":["226799909877807659285490770275639837796","262319790991739063364279623433161153928","74581169411709225073090025262717930354","664867752229300434178153250094377039","220166180862611395656168537984515288348","190559348327466607830251463642080103084","36166306246568003215501536439623036800","260458028198078392132216653541170342673","327740737921250843757776675491527687882","19318788253601659059027498180181400539","20982242232628166514688029097576168213","222613788378665974984707375594297806837","11991112549517534563528635106582658963","91096039064502450264305662829384932096","218640961339796131559535252972743599182","173880245933184051894152545564130220546","7308911191249598365786543875285117906","209253474040954115970794107289818101859","35551642934319494006734460242576762786","301498188223892945096981820007306153854","99606358875984692459733966296514913648","160302061576617993718488937012743287135","12462434668086025598119242186195946946","307266903725538188392143452036242870349","162289245472186640488504227465691293655","286296970952603245069765485750694385411","66650176159536853900465156155505256698","213881475579775202930925555780269184257","42775758973717697137286361274301416410","325646444715410066844947238010803221687","217429509776702288324962444975093948025","99910992131710471681879593996092630401","168729663854147352829288477888939428857","95942673609488616040507548799857288362","217429509776702288324962444975093948025","99910992131710471681879593996092630401","238485074102862404181517164462591736239","72687738435764000573608477025591424944","244450576278680018267515271633531514190","311378769205653024404310822312885158656","270199727046986186524237466536745643270"],"threshold":0.9},"id":"CVE-2026-35591-6f474f6d","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"length":1001,"function_hash":"298273362866700007392165939252667409108"},"id":"CVE-2026-35591-8eeccdcb","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe","target":{"file":"libvips/foreign/jp2kload.c","function":"vips_foreign_load_jp2k_check_supported"}},{"signature_version":"v1","source":"https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe","target":{"file":"libvips/foreign/jp2kload.c","function":"vips_foreign_load_jp2k_generate_tiled"},"deprecated":false,"digest":{"function_hash":"8313486697761689144862972010519137560","length":1975},"id":"CVE-2026-35591-c5d51fa9","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe","target":{"file":"libvips/foreign/jp2kload.c","function":"vips__foreign_load_jp2k_decompress"},"deprecated":false,"digest":{"function_hash":"93849039275936212560091913181534957033","length":1660},"id":"CVE-2026-35591-f6ebc548","signature_type":"Function"},{"target":{"file":"libvips/foreign/tiff2vips.c","function":"rtiff_decompress_jpeg_run"},"deprecated":false,"digest":{"length":1617,"function_hash":"140533827483987169618465145593423126993"},"id":"CVE-2026-35591-fb84885e","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/df044e409a0db77c980fa1a9f86a13fbfb2dc8fe"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"}]}