Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-52490: libtiff tiffcrop tool can let attackers run code
CVE-2026-52490 · published today
Summary
The libtiff image library, which many programs use to work with TIFF files, has a flaw in its tiffcrop utility that could allow a malicious user to run any program on the affected system. This could lead to loss of data or control of the server. Install the latest libtiff update or apply the vendor’s patch to close the gap.
What to do
- Update tiff to version 4.7.0-3+deb13u3.aikido.10.
- Update rootio-tiff to version 4.7.0-3+deb13u3.aikido.10.
- Update debian tiff to version 4.7.2-1.
- Update tiff to version 4.5.0-6+deb12u4.aikido.22.
- Update rootio-tiff to version 4.5.0-6+deb12u4.aikido.22.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:Debian:13 | – | tiff |
< 4.7.0-3+deb13u3.aikido.10 Fix: upgrade to 4.7.0-3+deb13u3.aikido.10
|
| Root:Debian:13 | – | rootio-tiff |
< 4.7.0-3+deb13u3.aikido.10 Fix: upgrade to 4.7.0-3+deb13u3.aikido.10
|
| Debian:11 | debian | tiff | All versions |
| Debian:12 | debian | tiff | All versions |
| Debian:13 | debian | tiff | All versions |
| Debian:14 | debian | tiff |
< 4.7.2-1 Fix: upgrade to 4.7.2-1
|
| Root:Debian:12 | – | tiff |
< 4.5.0-6+deb12u4.aikido.22 Fix: upgrade to 4.5.0-6+deb12u4.aikido.22
|
| Root:Debian:12 | – | rootio-tiff |
< 4.5.0-6+deb12u4.aikido.22 Fix: upgrade to 4.5.0-6+deb12u4.aikido.22
|
Original advisory text
CVE-2026-52490 in tiff - Patched by Root
Root has patched CVE-2026-52490 in the tiff package for Root:Debian:13. Multiple fixed versions available.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen24 Aug 2026
Monitor software like this
Free during beta