CVE-2026-35590
Description
libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.
How to fix CVE-2026-35590
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/vips—no fix listed
Is CVE-2026-35590 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-35590.
Affected packages (1)
- from 0