Description
GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of XWD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28265.
Published: 2026-02-20
Score: 7.3 High
EPSS: 4.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in GIMP’s handling of XWD files where insufficient validation of user-supplied data allows a write past the end of an allocated buffer. This out‑of‑bounds write can overwrite control data in the process, giving an attacker the ability to execute arbitrary code with the same privileges as the GIMP process. The vulnerability is limited to the XWD file parser and does not involve other file formats or components of the application.

Affected Systems

GIMP version 3.0.6 is the specifically identified affected build; other versions that still use the same XWD parsing code may also be impacted, but no additional products or vendors are listed as affected.

Risk and Exploitability

The CVSS base score of 7.3 indicates a high severity, while the EPSS score of 5% suggests that exploitation is moderately likely in the present environment. The vulnerability is not listed in CISA’s KEV catalog, reflecting that no publicly known exploits are currently documented. Exploitation requires user interaction, typically by opening a crafted XWD file or loading it through a web page that references the file; the attacker must thus entice or trick the user into executing the file. Given the remote code execution potential and the moderate EPSS probability, administrators should prioritize addressing this flaw quickly.

Generated by OpenCVE AI on August 4, 2026 at 08:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update GIMP to the latest release that contains the buffer‑overflow fix for XWD file parsing.
  • If an immediate update is not available, disable support for XWD files in GIMP to prevent the vulnerable parsing routine from executing.
  • Restrict untrusted file downloads and employ sandboxing or application whitelisting for environments where GIMP is used, ensuring that even if the file is opened, it cannot compromise the host system.

Generated by OpenCVE AI on August 4, 2026 at 08:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4500-1 gimp security updat
Debian DSA Debian DSA DSA-6156-1 gimp security update
History

Tue, 24 Feb 2026 21:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gimp:gimp:3.0.6:*:*:*:*:*:*:*

Tue, 24 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Gimp
Gimp gimp
Vendors & Products Gimp
Gimp gimp

Sat, 21 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 20 Feb 2026 22:30:00 +0000

Type Values Removed Values Added
Description GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XWD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28265.
Title GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Weaknesses CWE-787
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-07-15T01:20:41.398Z

Reserved: 2026-02-06T01:16:18.260Z

Link: CVE-2026-2045

cve-icon Vulnrichment

Updated: 2026-06-30T12:07:00.937Z

cve-icon NVD

Status : Modified

Published: 2026-02-20T23:16:04.847

Modified: 2026-07-15T02:19:27.877

Link: CVE-2026-2045

cve-icon Redhat

Severity : Important

Publid Date: 2026-02-20T22:23:32Z

Links: CVE-2026-2045 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:00:06Z

Weaknesses