VulnSea

gimp:2.8/gimp vulnerabilities

CVEs whose affected-version data names the gimp:2.8/gimp package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-96546Low· 2.5
yesterday

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. …

SunlitRed Hat · gimpvia NVD
CVE-2026-96545Medium· 4.4PoC
yesterday

An out-of-bounds heap read flaw was found in GIMP's TIM image loader

An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the l…

TwilightRed Hat · gimpvia NVD
CVE-2026-92248High· 7.8
1w ago

A flaw was found in the file-psd plugin in GIMP

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header…

TwilightGNOME · gimpEPSS 0.18%via NVD
CVE-2026-90947High· 7.8
1w ago

A flaw was found in GIMP

A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attack…

TwilightRed Hat · gimpEPSS 0.13%via NVD
CVE-2026-90949High· 7.8
1w ago

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. …

TwilightRed Hat · gimpEPSS 0.22%via NVD
CVE-2026-90948High· 7.8
1w ago

A flaw was found in GIMP's ICO file loader

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocate…

TwilightRed Hat · gimpEPSS 0.22%via NVD
gimp:2.8/gimp vulnerabilities (CVEs) · VulnSea