CVE-2026-103641Medium· 5.5▾ SunlitA flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than the width declared in the file header. Opening a crafted HDR file crashes the application that us…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than the width declared in the file header. Opening a crafted HDR file crashes the application that uses the loader.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102558High· 8.6A flaw was found in libsoup
CVE-2026-102555High· 8.2A flaw was found in libsoup
CVE-2026-102560High· 8.6A flaw was found in libsoup
CVE-2026-102559High· 8.6A flaw was found in libsoup
CVE-2026-102557High· 8.6A flaw was found in libsoup
CVE-2026-85644High· 7.5XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references, but it …