CVE-2026-35591
libvips libvips 취약점
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.
- 대응 우선순위
- 점검
- CVSS
- 7
- EPSS
- 0.13% 백분위 3.17% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.21