ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-92183, a stack-based buffer overflow in GIMP's APNG file parsing that enables remote code execution (CVSS 7.8).
ZDI published advisory ZDI-26-713 describing a stack-based buffer overflow in GIMP's APNG file parsing, assigned CVE-2026-92183 with a CVSS score of 7.8. Remote attackers can execute arbitrary code on affected installations, but exploitation requires user interaction such as visiting a malicious page or opening a malicious file. The advisory does not mention exploitation in the wild or patch status.
- Stack-based buffer overflow in GIMP APNG parsing, CVE-2026-92183
- Remote code execution rated CVSS 7.8
- Exploitation requires user interaction via malicious page or file
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92183 | NVD description · AI analysis pending | — | — | — | — | — |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92183.
This source does not provide full text. Read it at zerodayinitiative.com.