Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
1.9

libvips: Unauthenticated Local Data Exposure in Image Processing

CVE-2026-3282
Summary

A flaw in libvips 8.19.0 can allow an attacker with local access to read sensitive data from an image. This occurs when a specific input is manipulated in a way that bypasses security checks. To fix this issue, apply the available patch to the affected software.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
libvips libvips 8.19.0 –
Original title
A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument al...
Original description
A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alpha_band can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been published and may be used. This patch is called 7215ead1e0cd7d3703cc4f5fca06d7d0f4c22b91. A patch should be applied to remediate this issue.
nvd CVSS2.0 1.7
nvd CVSS3.1 7.1
nvd CVSS4.0 1.9
Vulnerability type
CWE-119 Buffer Overflow
CWE-125 Out-of-bounds Read
Published: 27 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026