Skip to content

GIMP vulnerabilities

3 CVEs tracked

GIMP, as an open-source image editor, appears in reports concerning vulnerabilities found in the processing of external file formats. The main theme involves multiple flaws triggered by specially crafted image files (FITS, PSD, PAA), leveraging issues like integer overflows and underflows. These vulnerabilities can lead to unexpected application behavior. Defenders should ensure that the relevant GIMP version addresses CVE-2026-66758, CVE-2026-59090, and CVE-2026-59091, and educate users to avoid opening files from untrusted sources with the application.

Azərbaycanca: GIMP, açıq mənbəli qrafik redaktoru olaraq, xüsusilə xarici fayl formatlarının işlənməsi zamanı kəşf edilən zəifliklərlə bağlı hesabatlarda görünür. Əsas mövzu, istifadəçiləri xüsusi hazırlanmış şəkil faylları (FITS, PSD, PAA) vasitəsilə hədəf alan müxtəlif boşluqlardır. Bu boşluqlar tam ədəd daşması (integer overflow) və ya azalması (underflow) kimi problemlərə səbəb olaraq gözlənilməz proqram davranışı ilə nəticələnə bilər. Müdafiəçilər, istifadə olunan GIMP versiyasında CVE-2026-66758, CVE-2026-59090 və CVE-2026-59091 zəifliklərinin aradan qaldırıldığına əmin olmalı, şübhəli mənbələrdən gələn faylları bu proqramla açmamaq barədə istifadəçiləri maarifləndirməlidir.

This vendor's CVEs3

This hub is built from skopnix's own reporting on GIMP: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.