CVE-2026-106062High· 7.8▾ TwilightA heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL (CWE-787), following integer overflow in size calculations (CWE-190). This may allow heap corruption and, in the worst case, arbitrary code execution in the context of the GIMP process.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106063Medium· 6.3A heap-based buffer overflow was found in GIMP’s DICOM export plug-in
CVE-2026-103531Medium· 5.5A flaw has been found in OpenSC up to 0.27.1
CVE-2026-6384High· 7.3A flaw was found in gimp
CVE-2026-59090High· 8.4A flaw was found in GIMP's PSD file format plugin
CVE-2026-66758High· 7.8A flaw was found in the file-fits plugin in GIMP
CVE-2026-97185High· 7.8A flaw was found in GIMP