CVE•Published 2026-08-20•Modified 2026-09-18•0 articles on news•5 live references•NVD data

CVE-2026-70651

Vulnerability data via NVD (ingested)

CVSS v3.1
—
EPSS percentile
2
Exploit Prediction Scoring System · top 98% of all CVEs
Description

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3.

Timeline
Published 2026-08-20
Modified 2026-09-18

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-70651 on GitHub.
We haven't classified any articles referencing CVE-2026-70651 yet. The external references above still apply.