CVE-2026-2913 describes a heap-based buffer overflow vulnerability in libvips versions up to 8.19.0, specifically within the vips_source_read_to_memory function in source.c. This flaw, rated High severity with a CVSS score of 7.0, requires local access and has high attack complexity, making exploitation difficult. While the exploit has been publicly disclosed, its impact is considered negligible as it primarily affects custom seekable sources larger than 4 GiB, with crashes occurring in user code rather than libvips itself. There is no evidence of active exploitation, Metasploit or ExploitDB modules, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.19.0CPE matchmatch criteria | cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.