CVE-2026-59091
PoC massOut-of-bounds write in GIMP PSD/PAA file format plugins
CVE-2026-59091 is an out-of-bounds write flaw (CWE-787) in GIMP's file format import plugins, including the parsers for Adobe PSD and PAA image files. It is triggered when a user opens a specially crafted image file in GIMP, requiring no further interaction, which is why the CVSS vector includes user interaction (UI:R) with a local attack vector. Depending on the file, the parsing bug leads to unexpected application behavior such as crashes or memory corruption, with the high-scoring CIA impact (C:H/I:H/A:H) indicating potential for broader security impact if exploited. Anyone running an affected GIMP build is exposed, including users of Red Hat Enterprise Linux where GIMP is packaged and shipped by Red Hat (the CNA). There is no evidence of exploitation in the wild (not in CISA KEV, EPSS ~0.4%), but a public reference exists on the GIMP GitLab tracker, and patched builds are expected via GIMP and Red Hat security updates.
What to do: Update GIMP as soon as a patched release is published and apply the corresponding Red Hat Enterprise Linux errata for the gimp package; check installed versions via your package manager (e.g., 'rpm -q gimp' on RHEL) and the GIMP GitLab issue for fixed-version details. As an interim mitigation, avoid opening untrusted or unsourced PSD and PAA image files in GIMP, and restrict which users on shared or multi-user systems can open external image files.
| gimp | — |
| redhat enterprise linux | Red Hat Enterprise Linux shipments of the gimp package (affected package/version ranges per Red Hat; not enumerated in the source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction.
In the news0 stories
No ingested article mentions this CVE yet.