CVE-2026-36849: [CVE-2026-36849] libtiff: Denial of Service via large SamplesPerPixel tag
Published Jun 17, 2026
·Updated
Affected Software
1 affected component
LibTIFF libtiff
Frequently Asked Questions
1
What is the severity of CVE-2026-36849?
CVE-2026-36849 has been classified as a medium severity vulnerability.
2
How does CVE-2026-36849 affect users of LibTIFF?
CVE-2026-36849 can lead to a denial of service when processing TIFF images with large SamplesPerPixel tags.
3
How do I fix CVE-2026-36849?
To fix CVE-2026-36849, update to the latest version of LibTIFF that addresses this vulnerability.
4
Are there workarounds for CVE-2026-36849?
As a workaround for CVE-2026-36849, users should avoid processing untrusted TIFF files until a fix is applied.
5
Which versions of LibTIFF are affected by CVE-2026-36849?
CVE-2026-36849 affects certain versions of LibTIFF prior to the security update released on June 17, 2026.