CVE-2026-3146Disclosure(libvips / libvips)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The identifier of the patch is d4ce337c76bff1b278d7085c3c4f4725e3aa6ece. To fix this issue, it is recommended to deploy a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-404CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libvips

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
libvips

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-25: 2Technical Details · 2026-02-25: 202-25
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3146 A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. T… https://www.cve.org/CVERecord?id=CVE-2026-3146

    Post summary

    A new CVE-2026-3146 vulnerability was identified in libvips up to version 8.18.0, affecting the vips_foreign_load_matrix_header function, with no PoC, exploit, or patch details provided.

    00000115
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3146 Null Pointer Dereference Vulnerability in libvips Foreign Matrix Load Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3146

    Post summary

    A brief notice of CVE-2026-3146, a null pointer dereference in libvips' foreign matrix load function, with a link to a vulnerability details page.

    0000039
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibvipslibvips---

Explore more