Heap-based Buffer Overflow in GIMP TIF File Parser
CVE-2026-18302

7.8HIGH

Key Information:

Vendor

Gimp

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-18302?

A vulnerability in the GIMP's parsing of TIF files allows remote attackers to execute arbitrary code. This flaw stems from inadequate validation of the length of user-supplied data during the copying process to a heap-based buffer. Exploitation requires user action, such as visiting a malicious webpage or opening a specially crafted TIF file. If successfully executed, an attacker can execute code within the context of the current process, potentially compromising the system's integrity.

Affected Version(s)

GIMP 3.2.2

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.