CVE-2026-107167Medium· 6.2▾ SunlitA flaw was found in m17n-lib. A user providing specially crafted text input can trigger a heap use-after-free condition during input-method state transitions. Under specific conditions, the library frees an internal input context object …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A flaw was found in m17n-lib. A user providing specially crafted text input can trigger a heap use-after-free condition during input-method state transitions. Under specific conditions, the library frees an internal input context object but subsequently attempts to write to that freed memory. This issue can cause applications relying on the library to crash, leading to a Denial of Service (DoS), or potentially allow arbitrary code execution.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107169Medium· 6.2A flaw was found in m17n-lib
CVE-2026-107168Medium· 6.2A flaw was found in m17n-lib
CVE-2026-107170Low· 2.9A flaw was found in m17n-lib
CVE-2026-106065Medium· 6.3A heap-based buffer overflow was found in GIMP’s PCX export plug-in
CVE-2026-107174Medium· 6.4A flaw was found in source-to-image
CVE-2026-106064Medium· 6.3A heap-based buffer overflow was found in GIMP’s GIF export plug-in