{"api_version":"v1","generated_at":"2026-10-06T21:35:00+00:00","product":{"cve_count":12,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-libvips-libvips-db6bd7f3e6fb","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/libvips","name":"libvips","next_cursor":null,"observations":[{"affected":"libvips: < 8.18.3","affected_versions_present":true,"cve_id":"CVE-2026-70654","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-70654","fixed":"8.18.3.","last_modified":"2026-08-21T11:35:46.559Z","patch_url":"https://github.com/libvips/libvips/security/advisories/GHSA-rjmm-3qch-m9rg","primary_source":"","published":"2026-08-20T21:07:25.540Z"},{"affected":"libvips: < 8.18.3","affected_versions_present":true,"cve_id":"CVE-2026-70653","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-70653","fixed":"8.18.3.","last_modified":"2026-08-21T15:37:17.272Z","patch_url":"https://github.com/libvips/libvips/security/advisories/GHSA-fh99-55jf-5hj3","primary_source":"","published":"2026-08-20T21:06:26.424Z"},{"affected":"libvips: < 8.18.3","affected_versions_present":true,"cve_id":"CVE-2026-70651","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-70651","fixed":"8.18.3.","last_modified":"2026-08-25T15:25:19.181Z","patch_url":"https://github.com/libvips/libvips/security/advisories/GHSA-7p29-wg2h-36q4","primary_source":"","published":"2026-08-20T21:05:38.765Z"},{"affected":"libvips: < 8.18.3","affected_versions_present":true,"cve_id":"CVE-2026-70652","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-70652","fixed":"8.18.3.","last_modified":"2026-08-21T21:45:43.586Z","patch_url":"https://github.com/libvips/libvips/security/advisories/GHSA-h27h-jf9v-m8rg","primary_source":"","published":"2026-08-20T21:04:51.898Z"},{"affected":"libvips: < 8.18.3","affected_versions_present":true,"cve_id":"CVE-2026-69242","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-69242","fixed":"8.18.3.","last_modified":"2026-08-21T16:20:09.170Z","patch_url":"https://github.com/libvips/libvips/security/advisories/GHSA-9rwc-f68v-4482","primary_source":"","published":"2026-08-20T21:02:58.466Z"},{"affected":"<= 8.18.1","affected_versions_present":true,"cve_id":"CVE-2026-35591","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35591","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-20T17:44:01.158Z","patch_url":"https://github.com/libvips/libvips/security/advisories/GHSA-523x-vhfw-6r76","primary_source":"","published":"2026-07-20T16:24:50.831Z"},{"affected":"<= 8.18.1","affected_versions_present":true,"cve_id":"CVE-2026-35590","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35590","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-20T19:03:42.733Z","patch_url":"https://github.com/libvips/libvips/pull/4972","primary_source":"","published":"2026-07-20T16:23:33.905Z"},{"affected":"<= 8.18.0","affected_versions_present":true,"cve_id":"CVE-2026-33328","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33328","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-21T15:58:57.209Z","patch_url":"https://github.com/libvips/libvips/pull/4935","primary_source":"","published":"2026-07-20T16:22:22.378Z"},{"affected":"<= 8.18.0","affected_versions_present":true,"cve_id":"CVE-2026-33327","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33327","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-20T19:07:38.256Z","patch_url":"https://github.com/libvips/libvips/pull/4934","primary_source":"","published":"2026-07-20T16:21:16.663Z"},{"affected":"< 8.17.2","affected_versions_present":true,"cve_id":"CVE-2025-59933","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59933","fixed":"8.17.2.","last_modified":"2025-12-24T14:49:49.725Z","patch_url":"https://github.com/libvips/libvips/security/advisories/GHSA-q8px-4w5q-c2r4","primary_source":"","published":"2025-09-29T22:04:09.404Z"},{"affected":"< 8.16.1","affected_versions_present":true,"cve_id":"CVE-2025-29769","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-29769","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-30T22:03:02.869Z","patch_url":"https://github.com/libvips/libvips/security/advisories/GHSA-f8r8-43hh-rghm","primary_source":"","published":"2025-04-07T20:09:30.971Z"},{"affected":"< 8.14.4","affected_versions_present":true,"cve_id":"CVE-2023-40032","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-40032","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T17:03:21.242Z","patch_url":"https://github.com/libvips/libvips/security/advisories/GHSA-33qp-9pq7-9584","primary_source":"","published":"2023-09-11T18:34:59.025Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"libvips"}}
