Junglewise Threat Intelligence

CVE-2026-18305: GIMP TIF file parsing integer overflow

CVE-2026-18305 · Severity: high · CVSS 7.8 · Published 2026-08-20

Technologies: Gimp. Vendors: Gimp, Gnome.

Executive brief

GIMP is a popular open-source image editor used by designers and photographers to create and manipulate images. An integer overflow vulnerability in GIMP's TIF file parsing allows attackers to execute arbitrary code if a user opens a maliciously crafted TIF image file. Exploitation could result in complete system compromise, including theft of sensitive work or credentials stored on the affected user's computer.

Technical details

This vulnerability is an integer overflow in GIMP's TIF (Tagged Image File) parsing routine. The flaw stems from insufficient validation of user-supplied data in TIF file headers, allowing an integer overflow during buffer allocation. When a victim opens a maliciously crafted TIF file, the overflow is triggered before memory is allocated for image data, enabling an attacker to write arbitrary code to memory. Exploitation requires user interaction (opening a malicious file) but does not require authentication or elevated privileges. GIMP has issued a patch available on their GitLab repository.

Affected products

  • GNOME GIMP <UNKNOWN>

Timeline

  • 2026-04-17: disclosed: Vulnerability reported to vendor
  • 2026-07-29: patched: Patch released; fix available at gitlab.gnome.org/GNOME/gimp/-/commit/0a45a2b51b877829ef523131b50c0eb2a933b8a1
  • 2026-07-29: advisory: Coordinated public release of advisory ZDI-26-458

References

Related threats