Libvips is a widely embedded image-processing library that, despite a narrow product footprint, achieves prominence through deep integration into media servers, content-management systems, and image-manipulation pipelines across web and desktop applications. Its vulnerability profile centers on memory-safety and buffer-handling issues—including heap-based buffer overflows, out-of-bounds reads, NULL-pointer dereferences, and improper memory-buffer restrictions—that are characteristic of native image-parsing code handling untrusted input. Defenders should track this vendor's releases closely and prioritize rebuilding or updating downstream applications that depend on it, since remediation at the library level propagates only when consumers rebuild; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libvips over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17534HIGH vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, leading to a use-after-free. | Oct 13, 2019 | 8.8 | 28 | NO | NO |
CVE-2026-3281HIGH A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument i | Feb 27, 2026 | 7.8 | 26 | NO | NO |
CVE-2026-3147HIGH A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-bas | Feb 25, 2026 | 7.8 | 26 | NO | NO |
CVE-2026-3145HIGH A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of the file libvips/foreign/m | Feb 25, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-59933HIGH libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips is compiled with support for PDF input via poppler, the pdfl | Sep 29, 2025 | 7.8 | 26 | NO | NO |
CVE-2018-7998HIGH In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a deni | Mar 9, 2018 | 7.5 | 25 | NO | NO |
CVE-2026-3283HIGH A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. The manipulation of the argument | Feb 27, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-3282HIGH A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation o | Feb 27, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-2913HIGH A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation caus | Feb 22, 2026 | 7.0 | 24 | NO | NO |
CVE-2026-3284MEDIUM A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_are | Feb 27, 2026 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libvips.
Media articles that mention a CVE ID that affects a product developed by Libvips — matched by CVE ID, not by vendor name.