Integer overflow in libvips - CVE-2026-33327
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to integer overflow in the vipsload operation when parsing a crafted image file with incorrectly determined dimensions. A remote attacker can supply a specially crafted image file to cause a denial of service or execute arbitrary code.