
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2044 is a remote code execution vulnerability in GIMP caused by the use of uninitialized memory during PGM file parsing. It affects GIMP version 3.0.6 and was reported to the vendor on November 11, 2025, with coordinated public disclosure on February 19, 2026. The vulnerability was discovered and reported anonymously through the Zero Day Initiative (ZDI-26-118). It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-908 (Use of Uninitialized Resource): GIMP's PGM file parser accesses memory before it has been properly initialized, leading to undefined behavior that an attacker can control to redirect execution flow. The attack vector is local (the file must be opened by the target user), with low attack complexity and no privileges required, but user interaction is necessary — the victim must open a maliciously crafted PGM image file or visit a page that triggers its loading. The fix is documented in the official GIMP repository merge request commit 112a5e038f0646eae5ae314988ec074433d2b365 (ZDI Advisory, GIMP MR).
Successful exploitation allows an attacker to execute arbitrary code in the context of the user running GIMP, resulting in high confidentiality, integrity, and availability impacts on the affected workstation. An attacker who achieves code execution could access sensitive files, install malware, or use the compromised session as a foothold for lateral movement within a network. The scope is limited to the current process and user context, but on systems where GIMP is run with elevated privileges or in shared environments, the risk is amplified (ZDI Advisory, Red Hat Bugzilla).
A proof-of-concept exploit is referenced in the ZDI advisory (ZDI-26-118), but there is no evidence of active in-the-wild exploitation as of the time of disclosure. The vulnerability was internally tracked as ZDI-CAN-28158 and credited to an anonymous researcher. The EPSS score is approximately 0.063% (0.000630), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (ZDI Advisory, Feedly).
bash, sh, cmd.exe, powershell, curl, wget, python) that are not typical for image editing workflows.GIMP has issued a patch addressing this vulnerability, available via the official GIMP repository (merge request commit 112a5e038f0646eae5ae314988ec074433d2b365). Red Hat has released errata for affected RHEL versions: RHSA-2026:4173 (RHEL 9), RHSA-2026:5113 (RHEL 8), and multiple extended support errata (RHSA-2026:5388 through RHSA-2026:5437) for various RHEL 8/9 variants. Debian and AlmaLinux have also issued updates. Until patching is complete, users should avoid opening PGM files from untrusted sources and consider restricting GIMP's use in environments that process potentially malicious image files (Red Hat Bugzilla, ZDI Advisory).
Heise Online covered the vulnerability with an article titled "Security update: Malicious code attacks on GIMP possible," highlighting the risk to end users who open untrusted image files (Heise). The Hacker Wire shared the advisory on Mastodon and Bluesky shortly after public disclosure. Pro-Linux.de also published multiple security notices covering the GIMP vulnerabilities. Community reaction has been moderate, with the primary focus on patching workstations where GIMP is actively used, given the requirement for user interaction.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."