Input validation error in libvips - CVE-2026-35590
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the EXIF decoder when processing crafted EXIF metadata. A remote attacker can supply specially crafted EXIF metadata to cause a denial of service.
The issue can result in a null pointer dereference and crash in libexif after invalid EXIF tag group ranges are passed for decoding.