Lovell Fuller

@lovell.info

Open source software maintainer, product developer and Internet technologist London, UK https://lovell.info

We've just published advisories for a number of libvips vulnerabilities that affect the prebuilt binaries provided by versions of sharp <= 0.34.5 If you use sharp with untrusted input, please upgrade to the latest version, currently 0.35.3, which provides libvips 8.18.3 github.com/lovell/sharp...

Vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

### Impact A number of vulnerabilities, two rated as "High" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency. Those processing untrusted input with ver...

github.com

Latest version of sharp (for Node.js image processing): 📦 Faster and safer installation, no more install scripts 🙌 Dual ESM/CJS 🖼️ Improved AVIF output quality and bit depth ☀️ Experimental support for HDR gain maps 👷 Transferable ArrayBuffer output for worker threads www.npmjs.com/package/sharp

npmjs.com