{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/libvips--8.18.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-33327"},{"id":"CVE-2026-33328"},{"id":"CVE-2026-35590"},{"id":"CVE-2026-35591"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["npm/sharp (\u003c 0.35.0)","libvips (\u003c 8.18.3)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","supply-chain","image-processing","npm","libvips"],"_cs_type":"advisory","_cs_vendors":["sharp"],"content_html":"\u003cp\u003eFour vulnerabilities, including two rated as \u0026quot;High\u0026quot; severity, have been discovered and subsequently patched in \u003ccode\u003elibvips\u003c/code\u003e, an image processing library, which affects downstream consumers such as the popular Node.js \u003ccode\u003esharp\u003c/code\u003e package. These vulnerabilities, identified as CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, and CVE-2026-35591, are present in \u003ccode\u003elibvips\u003c/code\u003e versions prior to 8.18.3. Organizations and developers using \u003ccode\u003esharp\u003c/code\u003e versions older than 0.35.0, or those with a globally installed \u003ccode\u003elibvips\u003c/code\u003e instance prior to 8.18.3, are at risk, particularly if they process untrusted input such as user-supplied image files. Exploitation of these vulnerabilities could lead to denial of service, information disclosure, or potentially arbitrary code execution depending on the specific vulnerability and system configuration, making timely patching critical for maintaining application stability and security.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eOrganizations utilizing the \u003ccode\u003esharp\u003c/code\u003e library (versions prior to 0.35.0) or \u003ccode\u003elibvips\u003c/code\u003e (versions prior to 8.18.3) for image processing are at risk, particularly if their applications handle untrusted input, such as images uploaded by users. While specific observed exploitation scenarios are not detailed, vulnerabilities in image processing libraries handling untrusted input commonly lead to severe consequences. Successful exploitation could result in denial of service (crashing the application), arbitrary code execution (allowing attackers to run malicious code on the server), or information disclosure, compromising the integrity, availability, and confidentiality of the affected systems and data. All sectors relying on image manipulation services from these libraries, from e-commerce to social media platforms, could be impacted.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003esharp\u003c/code\u003e package to version 0.35.3 or later to obtain the patched \u003ccode\u003elibvips\u003c/code\u003e 8.18.3, addressing CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, and CVE-2026-35591.\u003c/li\u003e\n\u003cli\u003eIf using a globally installed \u003ccode\u003elibvips\u003c/code\u003e, ensure it is updated to version 8.18.3 or newer to mitigate the vulnerabilities.\u003c/li\u003e\n\u003cli\u003eImplement the provided code workaround to block decoding of GIF, TIFF, and VIPS images if immediate patching of affected products \u003ccode\u003esharp (\u0026lt; 0.35.0)\u003c/code\u003e and \u003ccode\u003elibvips (\u0026lt; 8.18.3)\u003c/code\u003e is not possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T22:07:58Z","date_published":"2026-07-21T22:07:58Z","id":"https://feed.craftedsignal.io/briefs/2026-07-sharp-libvips-vulnerabilities/","summary":"Multiple high-severity vulnerabilities, including CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, and CVE-2026-35591, have been identified and patched in the libvips dependency used by the sharp image processing library, affecting users processing untrusted input with sharp versions prior to 0.35.0 or globally installed libvips prior to 8.18.3.","title":"Multiple High-Severity Vulnerabilities in sharp and libvips Image Processing Libraries","url":"https://feed.craftedsignal.io/briefs/2026-07-sharp-libvips-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Libvips (\u003c 8.18.3)","version":"https://jsonfeed.org/version/1.1"}