GNOME Vulnerabilities and Affected Products
Vulnerabilities associated with GIMP.
Products
Clear product- GLib10 vulnerabilities
- libsoup5 vulnerabilities
- Gdk-Pixbuf3 vulnerabilities
- GIMP3 vulnerabilities
- libxml23 vulnerabilities
- Evolution Data Server2 vulnerabilities
- libgsf2 vulnerabilities
- Ekiga1 vulnerability
- Epiphany1 vulnerability
- Evolution1 vulnerability
- Fonts Viewer1 vulnerability
- gdkpixbuf1 vulnerability
- gdm1 vulnerability
- GDM31 vulnerability
- glade1 vulnerability
- gnome-remote-desktop1 vulnerability
- gnome-shell1 vulnerability
- gvdb1 vulnerability
- librest1 vulnerability
- libxslt1 vulnerability
- malcontent1 vulnerability
- NetworkManager1 vulnerability
- Pango1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-66759HIGH | Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns imagesA flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pi… CWE-125Jul 27, 2026 | CVSS7.1v3.1 | EPSS0.214% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66757MEDIUM | Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi imagesA flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This integer overflow issue results in undefined behavior, aborting the plugin and causing a denial… CWE-190Jul 27, 2026 | CVSS5.5v3.1 | EPSS0.198% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-66758HIGH | Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits imagesA flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, pot… CWE-190Jul 27, 2026 | CVSS7.8v3.1 | EPSS0.251% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |