ZeroHour

CVE-2026-59091

PoC mass

Out-of-bounds write in GIMP PSD/PAA file format plugins

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-59091 is an out-of-bounds write flaw (CWE-787) in GIMP's file format import plugins, including the parsers for Adobe PSD and PAA image files. It is triggered when a user opens a specially crafted image file in GIMP, requiring no further interaction, which is why the CVSS vector includes user interaction (UI:R) with a local attack vector. Depending on the file, the parsing bug leads to unexpected application behavior such as crashes or memory corruption, with the high-scoring CIA impact (C:H/I:H/A:H) indicating potential for broader security impact if exploited. Anyone running an affected GIMP build is exposed, including users of Red Hat Enterprise Linux where GIMP is packaged and shipped by Red Hat (the CNA). There is no evidence of exploitation in the wild (not in CISA KEV, EPSS ~0.4%), but a public reference exists on the GIMP GitLab tracker, and patched builds are expected via GIMP and Red Hat security updates.

What to do: Update GIMP as soon as a patched release is published and apply the corresponding Red Hat Enterprise Linux errata for the gimp package; check installed versions via your package manager (e.g., 'rpm -q gimp' on RHEL) and the GIMP GitLab issue for fixed-version details. As an interim mitigation, avoid opening untrusted or unsourced PSD and PAA image files in GIMP, and restrict which users on shared or multi-user systems can open external image files.

Affected
gimp
redhat enterprise linuxRed Hat Enterprise Linux shipments of the gimp package (affected package/version ranges per Red Hat; not enumerated in the source data)
Estimated exposure
massmillions of GIMP users worldwide (desktop install base plus RHEL-managed GIMP packages) — GIMP is a widely installed cross-platform image editor shipped in the repositories of major Linux distributions including Red Hat Enterprise Linux and has a large cumulative download base, so a multi-million install base is plausible,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction.

Vendors
gimpredhat
Products
gimp, enterprise linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.