CVE-2026-97185High· 7.8▾ TwilightA flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting me…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90947High· 7.8A flaw was found in GIMP
CVE-2026-90949High· 7.8A flaw was found in GIMP's PSP (Paint Shop Pro) file loader
CVE-2026-90948High· 7.8A flaw was found in GIMP's ICO file loader
CVE-2025-15059High· 7.8GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-96545Medium· 4.4An out-of-bounds heap read flaw was found in GIMP's TIM image loader
CVE-2026-96546Low· 2.5A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader