CVE-2026-2913Disclosure(libvips / libvips)

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The attack's complexity is rated as high. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. Patch name: a56feecbe9ed66521d9647ec9fbcd2546eccd7ee. Applying a patch is the recommended action to fix this issue. The confirmation of the bugfix mentions: "[T]he impact of this is negligible, since this only affects custom seekable sources larger than 4 GiB (and the crash occurs in user code rather than libvips itself)."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libvips

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
libvips

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-22: 102-22
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2913 📊 Severity: 2.5 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2913 #CVE-2026-2913 #CVE #Low #CyberSecurity #InfoSec https://t.co/tAR49rcy6p

    Post summary

    A new low‑severity CVE (CVE‑2026‑2913) has been announced with minimal details; no PoC, exploit, patch, or technical specifics are provided.

    0000045
    57 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibvipslibvips---

Explore more