Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6491

20
FAUCET Score

CYBERSECURITY BRIEFING NOTE - CVE-2026-6491 OVERVIEW A heap-based buffer overflow vulnerability exists in libvips versions up to 8.18.2, specifically within the im_minpos_vec function in the deprecated vips7compat.c file used by the nip2 handler. The vulnerability is triggered through manipulation of the argument n parameter and is limited to the deprecated component of the library. The vendor has confirmed plans to remove the affected deprecated code in version 8.19. SEVERITY This vulnerability carries a CVSS 3.1 score of 5.3 (Medium) with a local attack vector requiring low privileges and no user interaction. The impact assessment indicates potential for confidentiality, integrity, and availability compromise. The FAUCET Risk Score of 32.0 and EPSS percentile positioning indicate this threat ranks lower than the majority of known CVEs, though the active status on the Hot List warrants monitoring. EXPLOITATION STATUS Public exploit disclosure has occurred and exploit code is available. However, this vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no indicators of active exploitation in the wild. The local attack requirement and deprecated code location limit real-world exploitation potential despite public availability of proof-of-concept code.

Impacted Technologies

VendorProductVersion(s)CPE
N/ALibvips
8.18.0, 8.18.1, 8.18.2CNA affected

CVSS Data

CVSS version used by this source: 4.0

1.9LOW

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 34th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / biniamf/pocs/tree/main/libvips_im_minpos_vec_oob
github.com / libvips/libvips
github.com / libvips/libvips/issues/4965
github.com / libvips/libvips/issues/4965
vuldb.com / submit/786994
vuldb.com / vuln/358035
vuldb.com / vuln/358035/cti