CVE-2026-59087
PoC massHeap overflow in GIMP Seattle FilmWorks loader can allow code execution
CVE-2026-59087 is a heap-based buffer overflow (CWE-787) in the Seattle FilmWorks file loader of GIMP, the open-source image editor. It is triggered when a user opens a specially crafted Seattle FilmWorks file, causing GIMP to write several kilobytes of attacker-controlled data past the end of a heap buffer. This memory corruption can crash the application (denial of service) and may allow arbitrary code execution with the privileges of the user running GIMP. Affected deployments include GIMP itself and Red Hat Enterprise Linux, which ships GIMP as packaged by Red Hat; the CVSS 3.1 vector (AV:L/UI:R) confirms that exploitation requires local user interaction with a malicious file. No in-the-wild exploitation is known: the flaw is not in CISA KEV, EPSS estimates only about a 0.5% chance of exploitation within 30 days (40th percentile), and one public proof-of-concept reference exists on the GIMP project tracker.
What to do: Inventory GIMP installations (including GIMP packages shipped on RHEL hosts) and upgrade to the patched release as soon as Red Hat or GNOME publishes a fixed version; fixed version numbers are not given in the available data, so consult the Red Hat advisory and the upstream GIMP tracker item (gitlab.gnome.org/GNOME/gimp/-/work_items/16491). Until patching, avoid opening Seattle FilmWorks files from untrusted sources and consider disabling the SFW loader where it is unused. Because the flaw is local and requires user interaction, no network-level mitigation is needed; user awareness against untrusted image files is the primary interim defense.
| gimp (GNOME) GIMP image editor | — |
| redhat Red Hat Enterprise Linux | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.
In the news0 stories
No ingested article mentions this CVE yet.