CVE-2026-6491

Source
https://cve.org/CVERecord?id=CVE-2026-6491
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-6491.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-6491
Downstream
Published
2026-04-17T13:45:11.506Z
Modified
2026-07-11T03:54:25.327846050Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
libvips nip2 vips7compat.c im_minpos_vec heap-based overflow
Details

A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function imminposvec of the file libvips/deprecated/vips7compat.c of the component nip2 Handler. Such manipulation of the argument n leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor confirms that they will "be removing the deprecated area in libvips 8.19".

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6491.json",
    "cwe_ids": [
        "CWE-119",
        "CWE-122"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/libvips/libvips

Affected ranges

Type
GIT
Repo
https://github.com/libvips/libvips
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "8.18.0"
        },
        {
            "last_affected": "8.18.0"
        },
        {
            "introduced": "8.18.1"
        },
        {
            "last_affected": "8.18.1"
        },
        {
            "introduced": "8.18.2"
        },
        {
            "last_affected": "8.18.2"
        }
    ]
}

Affected versions

8.*
8.18.0
8.18.1
8.18.2
v8.*
v8.18.0
v8.18.1
v8.18.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-6491.json"