CVE-2026-69242
Last modified
CVE-2026-69242 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. The resulting buffer-region calculation can access attacker-controlled negative offsets in mmap-resident allocations, allowing reads or writes of other image data, possible data disclosure through uncompressed .v output, and likely process crashes. Remote code execution has not been demonstrated but cannot be ruled out. This issue is fixed in version 8.18.3.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| libvips | libvips | < 8.18.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-69242?
How severe is CVE-2026-69242?
How do I fix CVE-2026-69242?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69235There is a stored cross site scripting issue in Esri Portal …6.1
- CVE-2026-69236There is a stored cross site scripting issue in Esri Portal …6.1
- CVE-2026-69237There is an HTML injection vulnerability in Esri Portal for …4.8
- CVE-2026-69238There is an HTML injection vulnerability in Esri Portal for …4.8
- CVE-2026-6924A bug in the entropy initialization for SiWx917 causes the D…8.7
- CVE-2026-69240Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL inject…9.8
- CVE-2026-69243AIOHTTP is an asynchronous HTTP client/server framework for …6.3
- CVE-2026-69244AIOHTTP is an asynchronous HTTP client/server framework for …7.1
- CVE-2026-69245Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and…6.5
- CVE-2026-69246Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and…7.2
- CVE-2026-69247cryptography is a package designed to expose cryptographic p…8.2
- CVE-2026-69248cryptography is a package designed to expose cryptographic p…6.9
Are you affected by CVE-2026-69242?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
