CVE-2026-70652 | libvips up to 8.18.2 Uhdrsave uhdrsave.c vips_foreign_save_uhdr_set_raw_hdr heap-based overflow
A vulnerability was found in libvips up to 8.18.2. It has been declared as critical. Impacted is the function vips_foreign_save_uhdr_set_raw_hdr of the file libvips/foreign/uhdrsave.c of the component Uhdrsave. The manipulation results in heap-based buffer overflow.
This vulnerability is reported as CVE-2026-70652. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More