Heap-based Buffer Overflow in GIMP Image Editing Software
CVE-2026-2049

7.8HIGH

Key Information:

Vendor

Gimp

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-2049?

A serious vulnerability in GIMP is caused by improper validation during the parsing of HDR files. This flaw could lead to a heap-based buffer overflow, enabling remote attackers to execute arbitrary code on the affected installations. To exploit this vulnerability, the target user must either visit a malicious web page or open a specifically crafted HDR file that triggers the flaw. It is critical for users to ensure they are running the latest version of GIMP to mitigate this risk. Further details can be found in the advisory from Zero Day Initiative and the vendor-specific information.

Affected Version(s)

GIMP 3.2.0-RC1

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.