Heap-based Buffer Overflow in GIMP Affects Remote Code Execution
CVE-2026-2050
7.8HIGH
What is CVE-2026-2050?
This vulnerability within GIMP's HDR file parsing functionality enables remote attackers to execute arbitrary code on vulnerable installations. The flaw arises from inadequate validation of the size of user-supplied data before it is copied to a heap-allocated buffer. To exploit this issue, an attacker must coax the victim into either visiting a malicious webpage or manipulating a specially crafted file. Successful exploitation of this vulnerability could lead to unauthorized access and potential compromise of the affected system.
Affected Version(s)
GIMP 3.0.6
