CVE-2026-59090High· 8.4▾ MidnightPoC availableA flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, en…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 46.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.6%
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the block_rem variable, occurs when a user opens a specially crafted .psd image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.
gimp 3.3.1gimp (all versions)gimp (all versions)gimpgimp (all versions)gimp (all versions)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
To mitigate this vulnerability, users should avoid opening untrusted or suspicious PSD image files with GIMP. As a general security practice, it is recommended to only process image files from trusted sources.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-66758High· 7.8Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits images
CVE-2026-42169High· 7.3Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c)
CVE-2026-58384High· 7.3A flaw was found in GIMP's PSD parser
CVE-2026-58380High· 7.3A flaw was found in GIMP's PNM file format parser
CVE-2026-58379High· 7.3A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser
CVE-2026-96545Medium· 4.4An out-of-bounds heap read flaw was found in GIMP's TIM image loader