CVE-2026-93019: Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read
CVE-2026-93019: Imager for Perl versions before 1.036 exit the process when reading a TGA image with a colour map length of 32768 or more.
Stig Palmquist disclosed CVE-2026-93019, a denial-of-service flaw in the Imager image library for Perl. Versions before 1.036 terminate the process inside tga_palette_read when parsing a TGA file with a colour map length of 32768 or greater, allowing a crafted image to crash any application that processes untrusted files. The issue is fixed in Imager 1.036; no exploitation has been reported.