Heap-based Buffer Overflow in GIMP Image Editing Software
CVE-2026-2049
7.8HIGH
What is CVE-2026-2049?
A serious vulnerability in GIMP is caused by improper validation during the parsing of HDR files. This flaw could lead to a heap-based buffer overflow, enabling remote attackers to execute arbitrary code on the affected installations. To exploit this vulnerability, the target user must either visit a malicious web page or open a specifically crafted HDR file that triggers the flaw. It is critical for users to ensure they are running the latest version of GIMP to mitigate this risk. Further details can be found in the advisory from Zero Day Initiative and the vendor-specific information.
Affected Version(s)
GIMP 3.2.0-RC1
