<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Libvips - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/libvips/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 21 Jul 2026 22:07:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/libvips/feed.xml" rel="self" type="application/rss+xml"/><item><title>Multiple High-Severity Vulnerabilities in sharp and libvips Image Processing Libraries</title><link>https://feed.craftedsignal.io/briefs/2026-07-sharp-libvips-vulnerabilities/</link><pubDate>Tue, 21 Jul 2026 22:07:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-sharp-libvips-vulnerabilities/</guid><description>Multiple high-severity vulnerabilities, including CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, and CVE-2026-35591, have been identified and patched in the libvips dependency used by the sharp image processing library, affecting users processing untrusted input with sharp versions prior to 0.35.0 or globally installed libvips prior to 8.18.3.</description><content:encoded><![CDATA[<p>Four vulnerabilities, including two rated as &quot;High&quot; severity, have been discovered and subsequently patched in <code>libvips</code>, an image processing library, which affects downstream consumers such as the popular Node.js <code>sharp</code> package. These vulnerabilities, identified as CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, and CVE-2026-35591, are present in <code>libvips</code> versions prior to 8.18.3. Organizations and developers using <code>sharp</code> versions older than 0.35.0, or those with a globally installed <code>libvips</code> instance prior to 8.18.3, are at risk, particularly if they process untrusted input such as user-supplied image files. Exploitation of these vulnerabilities could lead to denial of service, information disclosure, or potentially arbitrary code execution depending on the specific vulnerability and system configuration, making timely patching critical for maintaining application stability and security.</p>
<h2 id="impact">Impact</h2>
<p>Organizations utilizing the <code>sharp</code> library (versions prior to 0.35.0) or <code>libvips</code> (versions prior to 8.18.3) for image processing are at risk, particularly if their applications handle untrusted input, such as images uploaded by users. While specific observed exploitation scenarios are not detailed, vulnerabilities in image processing libraries handling untrusted input commonly lead to severe consequences. Successful exploitation could result in denial of service (crashing the application), arbitrary code execution (allowing attackers to run malicious code on the server), or information disclosure, compromising the integrity, availability, and confidentiality of the affected systems and data. All sectors relying on image manipulation services from these libraries, from e-commerce to social media platforms, could be impacted.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>sharp</code> package to version 0.35.3 or later to obtain the patched <code>libvips</code> 8.18.3, addressing CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, and CVE-2026-35591.</li>
<li>If using a globally installed <code>libvips</code>, ensure it is updated to version 8.18.3 or newer to mitigate the vulnerabilities.</li>
<li>Implement the provided code workaround to block decoding of GIF, TIFF, and VIPS images if immediate patching of affected products <code>sharp (&lt; 0.35.0)</code> and <code>libvips (&lt; 8.18.3)</code> is not possible.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>supply-chain</category><category>image-processing</category><category>npm</category><category>libvips</category></item></channel></rss>