{"id":"CVE-2026-33327","summary":"Possible integer overflow leading to potential heap-based buffer overflow","details":"libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.","aliases":["GHSA-2fcj-gj27-279x"],"modified":"2026-07-22T08:28:15.441279Z","published":"2026-07-20T16:21:16.663Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33327.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-190"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33327.json"},{"type":"ADVISORY","url":"https://github.com/libvips/libvips/security/advisories/GHSA-2fcj-gj27-279x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33327"},{"type":"FIX","url":"https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9"},{"type":"FIX","url":"https://github.com/libvips/libvips/pull/4934"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libvips/libvips","events":[{"introduced":"0"},{"fixed":"61e71c13328ed72d0a530dffc19b9b225072bdf9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"8.18.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v8.18.0","v8.18.0-rc3","v8.18.0-rc2","v8.18.0-rc1","v8.18.0-alpha2","v8.18.0-alpha1","v8.17.0-rc1","v8.17.0","v8.17.0-test4","v8.17.0-test3","v8.17.0-test2","v8.17.0-test1","v8.16.0","v8.16.0-rc2","v8.16.0-rc1","v8.15.0","v8.15.0-rc2","v8.14.0","v8.14.0-rc1","v8.13.0","v8.13.0-rc2","v8.13.0-rc1","v8.13.0-pre1","v8.12.0","v8.12.0-rc1","v8.11.0","v8.11","v8.11.0-rc1","v8.10.6-beta2","v8.10.0","v8.10.0-rc2","v8.10.0-rc1","v8.10.0-beta2","v8.10.0-beta1","v8.9.0","v8.9.0-rc4","v8.9.0-rc3","v8.9.0-rc2","v8.9.0-rc1","v8.9.0-beta2","v8.9.0-beta1","v8.9.0-alpha1","v8.8.0-rc3","v8.8.0","v8.8.0-rc2","v8.8.0-rc1","v8.7.0","v8.7.0-rc3","v8.7.0-rc2","v8.7.0-rc1","v8.7.0-alpha2","v8.6.0","v8.6.0-beta2","v8.6.0-beta1","v8.6.0-alpha2","v8.6.0-alpha1","v8.5.3","v8.5.2","v8.5.1","v8.3.0","v8.2.2","v8.1","v8.0-beta","v7.28.0"],"database_specific":{"vanir_signatures":[{"target":{"file":"libvips/iofuncs/object.c","function":"vips_object_real_build"},"deprecated":false,"digest":{"function_hash":"143388755829374086000473818095288249890","length":472},"id":"CVE-2026-33327-003d39ad","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9"},{"source":"https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9","target":{"file":"libvips/iofuncs/image.c"},"deprecated":false,"digest":{"line_hashes":["223480178086453787758278101131898914023","234109384368306172353704833698790472522","203026080740743270553777003150943660021","248141106496541395162563418364402220617","339954748138605696925252810262295272885","13772120599242725202695205406644807555","290945251364916201926030577727999565048","28952029360003528383911986693415495998","94852133193140340522014995263817466447","156307606320818711184458339415991190381","68258179252485364908224457038677793119","154924044923671274225407175476418747120","256469169406346963090255168939248706891","199487052798995775728366738072546101363","42367196625450845047475095465279850500","97046239578848936430317252861049987165","86209948823509730988730590290245118086","98111944504458370823792203190881803758","328604566234503360421637311794720751543","339281787114015736839789416465932456995","268292218123558155747608856266121054333","161650081762172514091200439668273605261","333402744843380120209399108178115064391","64918344687275377627097621748918497969","327283146037136802408874656781483404698","132248055333387100583677680915338084821","107577196072034127947986122354418583262","130127050308482253665868908424856385939","202046648355123045680049567066756720534","178791434624156141083113354471032309882","168930484512929450955871164240090586730","313314112781150994923980219013402316303","221314034702355828632611677649467611242"],"threshold":0.9},"id":"CVE-2026-33327-0db3dd71","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9","target":{"file":"libvips/iofuncs/image.c","function":"vips_image_write_prepare"},"deprecated":false,"digest":{"function_hash":"235409723021130373820335314141619391437","length":877},"id":"CVE-2026-33327-613a13bc","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"181643012072986684283103543519486481630","length":1078},"id":"CVE-2026-33327-70a3b6fe","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9","target":{"file":"libvips/iofuncs/image.c","function":"vips_image_sanity"}},{"digest":{"line_hashes":["55799577680472821362884523340459635882","283637038327270297070660887698697026321","171139218678004698631355228866167495725"],"threshold":0.9},"id":"CVE-2026-33327-942ebc33","signature_type":"Line","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9","target":{"file":"libvips/iofuncs/object.c"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9","target":{"file":"libvips/iofuncs/image.c","function":"vips_image_new_from_memory"},"deprecated":false,"digest":{"function_hash":"19156182895307988900939440773607157352","length":729},"id":"CVE-2026-33327-d928ead3"},{"deprecated":false,"digest":{"function_hash":"197515869315236039657997456147584749601","length":2735},"id":"CVE-2026-33327-e960ee89","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/61e71c13328ed72d0a530dffc19b9b225072bdf9","target":{"file":"libvips/iofuncs/image.c","function":"vips_image_build"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33327.json","vanir_signatures_modified":"2026-07-22T08:28:15Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"}]}