Junglewise Threat Intelligence

CVE-2026-59087: GIMP heap overflow in Seattle Filmworks file loader

CVE-2026-59087 · Severity: high · CVSS 7.8 · Published 2026-08-10

Technologies: Gimp. Vendors: Gimp.

Executive brief

GIMP is a popular open-source image manipulation program used by photographers and designers to edit and create images. A vulnerability in its Seattle Filmworks file loader allows attackers to craft malicious image files that, when opened by a user, can corrupt memory and potentially allow arbitrary code execution or crash the application, compromising the user's system or disrupting their work.

Technical details

The vulnerability is a heap buffer overflow in GIMP's Seattle Filmworks file loader. An attacker can craft a specially formatted Seattle Filmworks file that triggers the overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended heap buffer boundary. The attack requires user interaction (opening the malicious file). Successful exploitation can lead to memory corruption, arbitrary code execution with the privileges of the user running GIMP, or denial of service. Patches from the GIMP project should be monitored.

Affected products

  • GIMP GIMP <UNKNOWN>

Timeline

  • 2026-08-10: disclosed

References

Related threats