CVE-2026-33327
published 2026-07-20CVE-2026-33327: libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine…
PriorityP344high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.2th percentile
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code16 | sharp | >= 0 < 0.35.0 | 0.35.0 |
| libvips | libvips | < 8.18.1 | 8.18.1 |
| libvips | libvips | <= 8.18.0 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.0HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libvips: libvips: Arbitrary code execution via heap-based buffer overflow in vipsload
vendor_redhat·2026-07-20·CVSS 7.0
CVE-2026-33327 [HIGH] CWE-131 libvips: libvips: Arbitrary code execution via heap-based buffer overflow in vipsload
libvips: libvips: Arbitrary code execution via heap-based buffer overflow in vipsload
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
A flaw was found in libvips, an image processing library. The `vipsload` operation, responsible for loading images, could incorrectly calculate image dimensions. This error leads to an integer overflow, which subsequently causes a heap-based buffer overflow. A local attacker with low privileges could exploit this vulnerability to execute arbitrary code or cause the application to crash, leading to a denial of servic
GHSA
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
ghsa·2026-07-21·CVSS 7.0
CVE-2026-33327 [HIGH] CWE-1395 sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
### Impact
A number of vulnerabilities, two rated as "High" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.
Those processing untrusted input with versions of sharp prior to 0.35.0 are affected.
### Patches
#### Using prebuilt binaries provided by sharp?
Most people rely on the prebuilt binaries provided by sharp.
Please upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.
#### Using a globally-installed libvips?
Please ensure you are using the latest libvips 8.18.3.
### Workarounds
Add the following to your code to prevent sharp from decoding GIF, TIFF and VIPS images.
```js
sharp.block({ operation: [
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-33327 vips: libvips: Arbitrary code execution via heap-based buffer overflow in vipsload [fedora-all]
bugzilla·2026-08-13·CVSS 7.0
CVE-2026-33327 [HIGH] CVE-2026-33327 vips: libvips: Arbitrary code execution via heap-based buffer overflow in vipsload [fedora-all]
CVE-2026-33327 vips: libvips: Arbitrary code execution via heap-based buffer overflow in vipsload [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
Bugzilla
CVE-2026-33327 libvips: libvips: Arbitrary code execution via heap-based buffer overflow in vipsload
bugzilla·2026-07-20·CVSS 7.0
CVE-2026-33327 [HIGH] CVE-2026-33327 libvips: libvips: Arbitrary code execution via heap-based buffer overflow in vipsload
CVE-2026-33327 libvips: libvips: Arbitrary code execution via heap-based buffer overflow in vipsload
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
2026-07-20
Published