CVE-2026-59091 PUBLISHED

Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file

Assigner: redhat
Reserved: 02.07.2026 Published: 10.08.2026 Updated: 11.08.2026

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.3

Product Status

Vendor Red Hat
Product Red Hat Enterprise Linux 6
Versions Default: unknown
Vendor Red Hat
Product Red Hat Enterprise Linux 7
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 8
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 9
Versions Default: affected

Workarounds

Users should avoid opening untrusted image files, particularly those in PSD or PAA formats, with GIMP. Exercising caution with files from unknown or suspicious sources can prevent exploitation of these vulnerabilities.

References

Problem Types

  • Out-of-bounds Write CWE