CVE-2026-33327
Description
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
How to fix CVE-2026-33327
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/vips—no fix listed
Is CVE-2026-33327 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-33327.
Affected packages (1)
- from 0