CVE-2026-106066Medium· 6.3▾ SunlitA heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far less memory than GEGL reads or writes du…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far less memory than GEGL reads or writes during export, following integer overflow
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106067Medium· 6.3A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in
CVE-2026-106065Medium· 6.3A heap-based buffer overflow was found in GIMP’s PCX export plug-in
CVE-2026-106064Medium· 6.3A heap-based buffer overflow was found in GIMP’s GIF export plug-in
CVE-2026-106062High· 7.8A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader
CVE-2026-106063Medium· 6.3A heap-based buffer overflow was found in GIMP’s DICOM export plug-in
CVE-2026-106061Medium· 5.5A flaw was found in GIMP’s X cursor (XMC) thumbnail loader