SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-33328

MEDIUM · CVSS 6.8 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The `gifload` operation in libvips versions up to and including 8.18.0 on 32-bit systems is vulnerable to an integer overflow due to incorrect dimension calculations. This flaw could potentially lead to application crashes or arbitrary code execution. Users and organizations utilizing affected versions of libvips for image processing should prioritize upgrading to version 8.18.1 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-33328
Severity
MEDIUM
CVSS
6.8
EPSS
0.12%

Original NVD Description

libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1.