CVE-2026-6491Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of the component nip2 Handler. Such manipulation of the argument n leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor confirms that they will "be removing the deprecated area in libvips 8.19".

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-17); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-17: 1Mentions · 2026-04-19: 1Technical Details · 2026-04-17: 104-1704-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6491 A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of t… https://www.cve.org/CVERecord?id=CVE-2026-6491

    Post summary

    The text reports CVE‑2026‑6491 as a vulnerability in libvips up to version 8.18.2, identifies the affected function, but offers no further technical, PoC, exploitation, or patch information.

    00000148
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6491 Heap-Based Buffer Overflow in libvips up to 8.18.2 nip2 Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6491

    Post summary

    The tweet provides a brief disclosure of CVE-2026-6491, noting a heap-based buffer overflow in libvips up to version 8.18.2, without mentioning PoC, exploits, patches, or active exploitation.

    0000069
    4.0K followersView on X

Explore more