CYBERSECURITY BRIEFING NOTE - CVE-2026-6491 OVERVIEW A heap-based buffer overflow vulnerability exists in libvips versions up to 8.18.2, specifically within the im_minpos_vec function in the deprecated vips7compat.c file used by the nip2 handler. The vulnerability is triggered through manipulation of the argument n parameter and is limited to the deprecated component of the library. The vendor has confirmed plans to remove the affected deprecated code in version 8.19. SEVERITY This vulnerability carries a CVSS 3.1 score of 5.3 (Medium) with a local attack vector requiring low privileges and no user interaction. The impact assessment indicates potential for confidentiality, integrity, and availability compromise. The FAUCET Risk Score of 32.0 and EPSS percentile positioning indicate this threat ranks lower than the majority of known CVEs, though the active status on the Hot List warrants monitoring. EXPLOITATION STATUS Public exploit disclosure has occurred and exploit code is available. However, this vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no indicators of active exploitation in the wild. The local attack requirement and deprecated code location limit real-world exploitation potential despite public availability of proof-of-concept code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Libvips | 8.18.0, 8.18.1, 8.18.2CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.