gimp has 5 CVEs on record between 2025 and 2026. 2 were published in the last 90 days. The median CVSS is 7.3 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 2 prev 1
Worst active — by depth score
CVE-2026-2050High· 7.8GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability68CVE-2025-15059High· 7.8GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability68CVE-2026-58384High· 7.3A flaw was found in GIMP's PSD parser40CVE-2026-58380High· 7.3A flaw was found in GIMP's PNM file format parser40CVE-2025-6035Medium· 6.1A flaw was found in GIMP34
gimp vulnerabilities
CVEs affecting gimp, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-58384High· 7.3A flaw was found in GIMP's PSD parser
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory c…
CVE-2026-58380High· 7.3A flaw was found in GIMP's PNM file format parser
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the…
CVE-2026-2050High· 7.80dayGIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…
CVE-2025-15059High· 7.80dayGIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vu…
CVE-2025-6035Medium· 6.1A flaw was found in GIMP
A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image dimensions, such as width, height, and bytes-per-pixel (img_bpp), which can re…