libvips EXIF Decoder Null Pointer Dereference Vulnerability

Vulnerability

A null pointer dereference vulnerability has been identified in the EXIF decoder of libvips, a fast image processing library, in versions prior to and including 8.18.1. The vulnerability arises because the decoder did not properly validate the range of EXIF tag groups before sending the data to libexif, potentially leading to a crash.

Impact

Exploitation of this vulnerability can cause a null pointer dereference, resulting in a crash of the application.

Remediation

Users are advised to upgrade to libvips version 8.18.2 or later.

Added: Jul 20, 2026, 6:26 PM
Updated: Jul 20, 2026, 6:26 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
4.0
remediation
7.7
relevance
9.9
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.