
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59091 is an out-of-bounds write vulnerability (CWE-787) in GIMP's file format plugins, specifically affecting the PSD and PAA file parsers. A remote attacker can exploit this flaw by tricking a user into opening a specially crafted image file, potentially leading to arbitrary code execution, information disclosure, or application crash. The vulnerability was reported to Red Hat Bugzilla on July 2, 2026, and publicly disclosed on August 10, 2026. It carries a CVSS v3.1 base score of 7.3 (High), assigned by Red Hat as the CNA (Red Hat Advisory, Github Advisory).
The vulnerability stems from out-of-bounds write flaws (CWE-787) in GIMP's file-psd and file-paa plugins, which are installed by default. A source-level audit identified two distinct vulnerabilities in these plugins, both independently reproduced with standalone proof-of-concept files and confirmed via AddressSanitizer or arithmetic verification in a Fedora 41 Docker environment. Exploitation is triggered simply by opening a crafted image file via the standard "File > Open" dialog — no additional user interaction beyond that action is required. The write operations can corrupt memory, potentially allowing an attacker to modify control data such as return addresses to redirect execution (Red Hat Bugzilla, Red Hat Advisory).
Successful exploitation can result in arbitrary code execution with the privileges of the user running GIMP, unauthorized access to sensitive files readable by that user, or a denial-of-service condition via application crash. The attack vector is local, meaning the attacker must deliver the malicious file to the victim's system (e.g., via email, download, or shared storage) and rely on the user opening it in GIMP. While lateral movement potential is limited by the local scope, data theft and full user-level system compromise are realistic outcomes (Red Hat Advisory, Github Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is not automatable, as it requires user interaction to open the malicious file. The EPSS score is approximately 0.167%, placing it in the 6th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Notably, the Red Hat Bugzilla entry references that standalone PoC files were created internally during the audit, but these have not been publicly released (Red Hat Bugzilla, Github Advisory).
file-psd or file-paa plugin, exploiting improper bounds checking during file parsing.bash, sh, curl, wget, python) following the opening of a PSD or PAA file./tmp, or application data folders shortly after GIMP is used to open an image; new cron jobs or autostart entries created under the user account.gimp-2.x, gimp-3.x) referencing segmentation faults or heap corruption; AddressSanitizer-style error output if debug builds are in use.A patch has been made available; users should update GIMP to the fixed version as soon as it is released for their platform or distribution. Red Hat has confirmed the vulnerability affects GIMP packages in Red Hat Enterprise Linux and advises users to avoid opening PSD or PAA files from untrusted or unknown sources in the interim. As an additional control, organizations can implement application allowlisting or file type restrictions to limit which image formats users can open in GIMP. Users on affected systems should monitor for updated packages via their distribution's package manager (e.g., dnf update gimp on RHEL/Fedora) (Red Hat Advisory, Github Advisory).
The vulnerability was discussed briefly on Mastodon/Infosec.exchange via VulDB's account shortly after disclosure. Automated vulnerability tracking services including VulDB, Vulners, CVEFeed, and OSV.dev indexed the CVE rapidly on the day of publication. No significant vendor statements beyond Red Hat's advisory or notable independent researcher commentary have been identified at this time (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."