CVE-2026-66758High· 7.8▾ TwilightA flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, the…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.4%
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.
gimp (all versions)gimp:2.8 (all versions)gimp (all versions)gimp (all versions)gimp (all versions)gimp (all versions)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
To mitigate this vulnerability, do not open FITS files from untrusted sources with GIMP.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42169High· 7.3Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c)
CVE-2026-58384High· 7.3A flaw was found in GIMP's PSD parser
CVE-2026-58380High· 7.3A flaw was found in GIMP's PNM file format parser
CVE-2025-6035Medium· 6.1A flaw was found in GIMP
CVE-2026-59090High· 8.4Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
CVE-2026-92248High· 7.8A flaw was found in the file-psd plugin in GIMP