Junglewise Threat Intelligence

CVE-2026-18304: GIMP integer overflow in TIF file parsing

CVE-2026-18304 · Severity: high · CVSS 7.8 · Published 2026-08-20

Technologies: Gimp. Vendors: Gimp.

Executive brief

GIMP is a widely-used open-source image editor. A flaw in how it parses TIFF image files can allow an attacker to craft a malicious image that, when opened by a user, executes arbitrary code on their computer with the permissions of the GIMP process, potentially compromising sensitive image data or enabling further system compromise.

Technical details

The vulnerability is an integer overflow in GIMP's TIF file parser that occurs before buffer allocation. Insufficient validation of user-supplied data in TIFF files allows an attacker to trigger an integer overflow, leading to allocation of an undersized buffer. When subsequent operations write to this buffer, a heap overflow occurs, enabling arbitrary code execution. The attack requires user interaction (opening a malicious TIFF file), but is otherwise remote/local depending on delivery vector. GIMP has released a patch available at the GitLab commit referenced in the advisory.

Affected products

  • GIMP GIMP prior to patch (commit ad32d22c347674fa1bb5b60935c376b673d946e7)

Timeline

  • 2026-04-17: disclosed: Vulnerability reported to vendor
  • 2026-07-29: advisory: Coordinated public release of advisory (ZDI-26-457)
  • 2026-07-29: patched: GIMP patch available

References

Related threats