A vulnerability, which was classified as critical, was found in libvips up to 8.18.1. The impacted element is an unknown function of the component tiffload. Executing a manipulation can lead to buffer overflow.

This vulnerability is tracked as CVE-2026-35591. The attack can be launched remotely. No exploit exists.