
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2049 is a heap-based buffer overflow vulnerability in GIMP's HDR file parsing functionality that allows remote attackers to execute arbitrary code on affected installations. The flaw was reported to the vendor on December 24, 2025, and publicly disclosed on March 16, 2026, via the Zero Day Initiative advisory ZDI-26-214. It affects GIMP version 3.2.0-RC1, with the underlying flaw residing in the GEGL image processing library. The vulnerability carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Github Advisory).
The root cause is classified as CWE-122 (Heap-based Buffer Overflow): the HDR file parser in GEGL fails to validate the length of user-supplied data before copying it into a heap-allocated buffer, enabling an attacker to overwrite adjacent heap memory. Exploitation requires local access in the sense that the attack vector is local (the file must be opened by the target), but the attacker can deliver the malicious HDR file remotely — for example, via a malicious web page or email attachment — requiring only that the user open the crafted file. The vulnerability was tracked internally as ZDI-CAN-28618, and additional technical details are referenced in the upstream GEGL issue tracker (ZDI Advisory, Github Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the GIMP process, inheriting the privileges of the user running the application. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive files accessible to the user, modify or delete data, and crash the application. While the scope is limited to the current user process, the compromise could serve as a foothold for further lateral movement on multi-user systems (ZDI Advisory, Github Advisory).
A proof-of-concept exploit reference is available through the Zero Day Initiative advisory (ZDI-26-214), published March 16, 2026. There is no current evidence of active in-the-wild exploitation, and the NVD SSVC assessment confirms exploitation status as "none" at this time. The EPSS score is approximately 0.548% (42nd percentile), indicating a relatively low but non-negligible probability of exploitation within 30 days. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog (ZDI Advisory, Github Advisory).
/bin/sh, bash, curl, wget, python) immediately after opening an HDR file; GIMP process crashing or producing core dumps.GIMP has issued a patch addressing this vulnerability, with details referenced in the GEGL upstream issue tracker (https://gitlab.gnome.org/GNOME/gegl/-/issues/450). Downstream Linux distributions including Debian, Mageia, Amazon Linux 2, and SUSE have released updated packages for the GEGL library. Users should update GIMP and the underlying GEGL library to the patched versions provided by their distribution. As an interim workaround, users should avoid opening HDR files from untrusted sources, and administrators may consider restricting or disabling HDR file handling if not required (ZDI Advisory, Github Advisory).
Heise (a German technology publication) covered the vulnerability in an article titled "Gimp Update closes code smuggling vulnerabilities," indicating mainstream tech media attention. Social media activity was noted on Mastodon via @thehackerwire. Linux security community sites including LinuxSecurity.com and LinuxCompatible.org tracked the downstream distribution patches across Debian, Mageia, and SUSE. Overall community reaction has been measured, consistent with the moderate EPSS score and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."