{"schema_version":1,"title":"Gnome vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 89 vulnerabilities in Gnome: 9 in the last 7 days and 47 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91841, was published on 25 September 2026. 7 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/gnome","json_url":"https://junglewise.ai/threats/vendors/gnome.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/gnome","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":29,"all_time":89,"critical":1,"exploited":0,"last_7_days":9,"last_30_days":21,"last_90_days":47,"last_365_days":72},"latest":[{"cve":"CVE-2026-91841","cvss":7.8,"slug":"cve-2026-91841-a-flaw-was-found-in-networkmanager-vpnc-a-vpn-plugin-for","title":"NetworkManager-vpnc CA-File path newline injection privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-25T18:17:32.923+00:00","url":"https://junglewise.ai/threats/cve-2026-91841-a-flaw-was-found-in-networkmanager-vpnc-a-vpn-plugin-for"},{"cve":"CVE-2026-91840","cvss":7.8,"slug":"cve-2026-91840-a-flaw-was-found-in-networkmanager-vpnc-this-vulnerability-allows","title":"NetworkManager-vpnc privilege escalation via newline injection in VPN username","severity":"high","exploited":false,"published_at":"2026-09-25T18:17:32.793+00:00","url":"https://junglewise.ai/threats/cve-2026-91840-a-flaw-was-found-in-networkmanager-vpnc-this-vulnerability-allows"},{"cve":"CVE-2026-91838","cvss":7.8,"slug":"cve-2026-91838-a-flaw-was-found-in-networkmanager-sstp-the-sstp-vpn-plugin-for","title":"NetworkManager-sstp shell injection in VPN profile fields","severity":"high","exploited":false,"published_at":"2026-09-25T18:17:32.53+00:00","url":"https://junglewise.ai/threats/cve-2026-91838-a-flaw-was-found-in-networkmanager-sstp-the-sstp-vpn-plugin-for"},{"cve":"CVE-2026-91837","cvss":7.8,"slug":"cve-2026-91837-a-flaw-was-found-in-networkmanager-iodine-the-iodine-vpn-plugin","title":"NetworkManager-iodine command injection in nameserver option","severity":"high","exploited":false,"published_at":"2026-09-25T17:17:18.983+00:00","url":"https://junglewise.ai/threats/cve-2026-91837-a-flaw-was-found-in-networkmanager-iodine-the-iodine-vpn-plugin"},{"cve":"CVE-2026-97222","cvss":5.5,"slug":"cve-2026-97222-a-heap-use-after-free-flaw-was-found-in-gnumeric-when-a-user","title":"Gnumeric heap use-after-free in XML parsing","severity":"medium","exploited":false,"published_at":"2026-09-25T14:17:25.58+00:00","url":"https://junglewise.ai/threats/cve-2026-97222-a-heap-use-after-free-flaw-was-found-in-gnumeric-when-a-user"},{"cve":"CVE-2026-97185","cvss":7.8,"epss":0.0013,"slug":"cve-2026-97185-a-flaw-was-found-in-gimp-when-processing-a-specially-crafted","title":"GIMP out-of-bounds write in GIMPressionist plugin","severity":"high","exploited":false,"published_at":"2026-09-24T09:17:08.937+00:00","url":"https://junglewise.ai/threats/cve-2026-97185-a-flaw-was-found-in-gimp-when-processing-a-specially-crafted"},{"cve":"CVE-2026-96889","cvss":7.8,"epss":0.0013,"slug":"cve-2026-96889-a-flaw-was-found-in-librsvg-when-processing-an-svg-document","title":"librsvg use-after-free in XML entity parsing","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:27.587+00:00","url":"https://junglewise.ai/threats/cve-2026-96889-a-flaw-was-found-in-librsvg-when-processing-an-svg-document"},{"cve":"CVE-2026-96545","cvss":4.4,"epss":0.0018,"slug":"cve-2026-96545-an-out-of-bounds-heap-read-flaw-was-found-in-gimp-s-tim-image","title":"GIMP out-of-bounds heap read in TIM image loader","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:54.227+00:00","url":"https://junglewise.ai/threats/cve-2026-96545-an-out-of-bounds-heap-read-flaw-was-found-in-gimp-s-tim-image"},{"cve":"CVE-2026-96541","cvss":7.5,"epss":0.0079,"slug":"cve-2026-96541-a-denial-of-service-flaw-was-found-in-gnome-remote-desktop-an","title":"GNOME Remote Desktop denial-of-service in RDP connection handling","severity":"high","exploited":false,"published_at":"2026-09-23T19:19:54.08+00:00","url":"https://junglewise.ai/threats/cve-2026-96541-a-denial-of-service-flaw-was-found-in-gnome-remote-desktop-an"},{"cve":"CVE-2026-91786","cvss":6.1,"epss":0.0017,"slug":"cve-2026-91786-gnome-shell-out-of-bounds-read-in-remote-search-icon-rendering","title":"GNOME Shell out-of-bounds read in remote search icon rendering","severity":"medium","exploited":false,"published_at":"2026-09-15T11:17:12.58+00:00","url":"https://junglewise.ai/threats/cve-2026-91786-gnome-shell-out-of-bounds-read-in-remote-search-icon-rendering"},{"cve":"CVE-2026-88924","cvss":7,"epss":0.0011,"slug":"cve-2026-88924-gnome-gvfs-privilege-escalation-via-symlink-toctou-in-admin","title":"GNOME gvfs privilege escalation via symlink TOCTOU in admin daemon","severity":"high","exploited":false,"published_at":"2026-09-10T15:17:59.253+00:00","url":"https://junglewise.ai/threats/cve-2026-88924-gnome-gvfs-privilege-escalation-via-symlink-toctou-in-admin"},{"cve":"CVE-2026-88859","cvss":6.3,"epss":0.0053,"slug":"cve-2026-88859-evolution-arbitrary-javascript-execution-via-spoofed-vcard","title":"Evolution arbitrary JavaScript execution via spoofed vCard","severity":"medium","exploited":false,"published_at":"2026-09-10T12:16:33.98+00:00","url":"https://junglewise.ai/threats/cve-2026-88859-evolution-arbitrary-javascript-execution-via-spoofed-vcard"},{"cve":"CVE-2026-18090","cvss":6.1,"epss":0.0017,"slug":"cve-2026-18090-gdk-pixbuf-heap-out-of-bounds-read-in-icns-decompression","title":"gdk-pixbuf heap out-of-bounds read in ICNS decompression","severity":"medium","exploited":false,"published_at":"2026-09-08T23:17:22.76+00:00","url":"https://junglewise.ai/threats/cve-2026-18090-gdk-pixbuf-heap-out-of-bounds-read-in-icns-decompression"},{"cve":"CVE-2026-74859","cvss":6.8,"epss":0.0017,"slug":"cve-2026-74859-gnome-tweaks-path-traversal-in-shell-theme-installer","title":"GNOME Tweaks path traversal in shell theme installer","severity":"medium","exploited":false,"published_at":"2026-09-08T09:18:20.96+00:00","url":"https://junglewise.ai/threats/cve-2026-74859-gnome-tweaks-path-traversal-in-shell-theme-installer"},{"cve":"CVE-2026-85534","cvss":5.9,"epss":0.0053,"slug":"cve-2026-85534-libsoup-http-2-denial-of-service-via-buffer-overflow-in-data","title":"libsoup HTTP/2 denial of service via buffer overflow in data callback","severity":"medium","exploited":false,"published_at":"2026-09-04T11:17:19.627+00:00","url":"https://junglewise.ai/threats/cve-2026-85534-libsoup-http-2-denial-of-service-via-buffer-overflow-in-data"},{"cve":"CVE-2026-85197","cvss":7.6,"epss":0.0041,"slug":"cve-2026-85197-gnome-libsoup-heap-use-after-free-in-http-2-client","title":"GNOME libsoup heap use-after-free in HTTP/2 client","severity":"high","exploited":false,"published_at":"2026-09-04T08:17:16.677+00:00","url":"https://junglewise.ai/threats/cve-2026-85197-gnome-libsoup-heap-use-after-free-in-http-2-client"},{"cve":"CVE-2026-84270","cvss":4.3,"epss":0.0022,"slug":"cve-2026-84270-gnome-gvfs-buffer-overflow-in-mtp-backend","title":"GNOME gvfs buffer overflow in MTP backend","severity":"medium","exploited":false,"published_at":"2026-09-01T16:17:37.817+00:00","url":"https://junglewise.ai/threats/cve-2026-84270-gnome-gvfs-buffer-overflow-in-mtp-backend"},{"cve":"CVE-2026-84269","cvss":6.5,"epss":0.0045,"slug":"cve-2026-84269-gnome-gvfs-afp-backend-heap-buffer-overflow","title":"GNOME gvfs AFP backend heap buffer overflow","severity":"medium","exploited":false,"published_at":"2026-09-01T16:17:37.69+00:00","url":"https://junglewise.ai/threats/cve-2026-84269-gnome-gvfs-afp-backend-heap-buffer-overflow"},{"cve":"CVE-2026-84268","cvss":8.8,"epss":0.0061,"slug":"cve-2026-84268-gnome-gvfs-sftp-backend-heap-overflow","title":"GNOME gvfs SFTP backend heap overflow","severity":"high","exploited":false,"published_at":"2026-09-01T16:17:37.563+00:00","url":"https://junglewise.ai/threats/cve-2026-84268-gnome-gvfs-sftp-backend-heap-overflow"},{"cve":"CVE-2026-84267","cvss":4.3,"epss":0.0037,"slug":"cve-2026-84267-gnome-gvfs-sftp-buffer-read-vulnerability","title":"GNOME gvfs SFTP buffer read vulnerability","severity":"medium","exploited":false,"published_at":"2026-09-01T16:17:37.007+00:00","url":"https://junglewise.ai/threats/cve-2026-84267-gnome-gvfs-sftp-buffer-read-vulnerability"},{"cve":"CVE-2026-81893","cvss":4.7,"epss":0.0015,"slug":"cve-2026-81893-gdk-pixbuf-out-of-bounds-write-in-jpeg-icc-profile-parser","title":"gdk-pixbuf out-of-bounds write in JPEG ICC profile parser","severity":"medium","exploited":false,"published_at":"2026-08-27T20:18:57.043+00:00","url":"https://junglewise.ai/threats/cve-2026-81893-gdk-pixbuf-out-of-bounds-write-in-jpeg-icc-profile-parser"},{"cve":"CVE-2026-77652","cvss":7.8,"epss":0.0021,"slug":"cve-2026-77652-gnome-dia-wpg-heap-buffer-overflow-in-colormap-parser","title":"GNOME Dia WPG heap buffer overflow in colormap parser","severity":"high","exploited":false,"published_at":"2026-08-26T20:18:02.16+00:00","url":"https://junglewise.ai/threats/cve-2026-77652-gnome-dia-wpg-heap-buffer-overflow-in-colormap-parser"},{"cve":"CVE-2026-77658","cvss":7.8,"epss":0.002,"slug":"cve-2026-77658-dia-diagram-editor-stack-buffer-overflow-in-bus-objects","title":"Dia diagram editor stack buffer overflow in bus objects","severity":"high","exploited":false,"published_at":"2026-08-26T13:19:22.043+00:00","url":"https://junglewise.ai/threats/cve-2026-77658-dia-diagram-editor-stack-buffer-overflow-in-bus-objects"},{"cve":"CVE-2026-77680","cvss":5.3,"epss":0.0062,"slug":"cve-2026-77680-libsoup-http-range-header-algorithmic-complexity-denial-of","title":"libsoup HTTP Range header algorithmic complexity denial of service","severity":"medium","exploited":false,"published_at":"2026-08-25T21:17:46.243+00:00","url":"https://junglewise.ai/threats/cve-2026-77680-libsoup-http-range-header-algorithmic-complexity-denial-of"},{"cve":"CVE-2026-78322","cvss":6.5,"epss":0.0051,"slug":"cve-2026-78322-gnome-file-roller-stack-buffer-overflow-in-archive-parsing","title":"GNOME file-roller stack buffer overflow in archive parsing","severity":"medium","exploited":false,"published_at":"2026-08-25T08:18:10.583+00:00","url":"https://junglewise.ai/threats/cve-2026-78322-gnome-file-roller-stack-buffer-overflow-in-archive-parsing"}],"vendor":{"hub":true,"name":"Gnome","slug":"gnome","homepage":"https://www.gnome.org/","description":"GNOME is a free and open-source desktop environment for Unix-like operating systems.","url":"https://junglewise.ai/threats/vendors/gnome"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":9}],"most_severe":[{"cve":"CVE-2019-11068","cvss":9.8,"epss":0.0113,"slug":"cve-2019-11068-nokogiri-libxslt-protection-mechanism-bypass-via-crafted-url","title":"Nokogiri libxslt protection mechanism bypass via crafted URL","severity":"critical","exploited":false,"published_at":"2022-05-13T01:21:57+00:00","url":"https://junglewise.ai/threats/cve-2019-11068-nokogiri-libxslt-protection-mechanism-bypass-via-crafted-url"},{"cve":"CVE-2026-84268","cvss":8.8,"epss":0.0061,"slug":"cve-2026-84268-gnome-gvfs-sftp-backend-heap-overflow","title":"GNOME gvfs SFTP backend heap overflow","severity":"high","exploited":false,"published_at":"2026-09-01T16:17:37.563+00:00","url":"https://junglewise.ai/threats/cve-2026-84268-gnome-gvfs-sftp-backend-heap-overflow"},{"cve":"CVE-2026-1761","cvss":8.6,"epss":0.0095,"slug":"cve-2026-1761-gnome-libsoup-stack-based-buffer-overflow-in-multipart-response","title":"GNOME libsoup stack-based buffer overflow in multipart response parsing","severity":"high","exploited":false,"published_at":"2026-02-02T14:16:34.65+00:00","url":"https://junglewise.ai/threats/cve-2026-1761-gnome-libsoup-stack-based-buffer-overflow-in-multipart-response"},{"cve":"CVE-2026-0719","cvss":8.6,"epss":0.0056,"slug":"cve-2026-0719-gnome-libsoup-stack-buffer-overflow-in-ntlm-authentication","title":"GNOME libsoup stack buffer overflow in NTLM authentication","severity":"high","exploited":false,"published_at":"2026-01-08T13:15:43.283+00:00","url":"https://junglewise.ai/threats/cve-2026-0719-gnome-libsoup-stack-buffer-overflow-in-ntlm-authentication"},{"cve":"CVE-2025-14523","cvss":8.2,"epss":0.005,"slug":"cve-2025-14523-gnome-libsoup-http-request-smuggling-via-duplicate-host-headers","title":"GNOME libsoup HTTP request smuggling via duplicate Host headers","severity":"high","exploited":false,"published_at":"2025-12-11T13:15:58.983+00:00","url":"https://junglewise.ai/threats/cve-2025-14523-gnome-libsoup-http-request-smuggling-via-duplicate-host-headers"},{"cve":"CVE-2025-7425","cvss":7.8,"epss":0.0034,"slug":"cve-2025-7425-gnome-libxslt-heap-use-after-free-in-attribute-management","title":"GNOME libxslt heap use-after-free in attribute management","severity":"high","exploited":false,"published_at":"2025-07-10T14:15:27.877+00:00","url":"https://junglewise.ai/threats/cve-2025-7425-gnome-libxslt-heap-use-after-free-in-attribute-management"},{"cve":"CVE-2026-77652","cvss":7.8,"epss":0.0021,"slug":"cve-2026-77652-gnome-dia-wpg-heap-buffer-overflow-in-colormap-parser","title":"GNOME Dia WPG heap buffer overflow in colormap parser","severity":"high","exploited":false,"published_at":"2026-08-26T20:18:02.16+00:00","url":"https://junglewise.ai/threats/cve-2026-77652-gnome-dia-wpg-heap-buffer-overflow-in-colormap-parser"},{"cve":"CVE-2026-77658","cvss":7.8,"epss":0.002,"slug":"cve-2026-77658-dia-diagram-editor-stack-buffer-overflow-in-bus-objects","title":"Dia diagram editor stack buffer overflow in bus objects","severity":"high","exploited":false,"published_at":"2026-08-26T13:19:22.043+00:00","url":"https://junglewise.ai/threats/cve-2026-77658-dia-diagram-editor-stack-buffer-overflow-in-bus-objects"},{"cve":"CVE-2026-97185","cvss":7.8,"epss":0.0013,"slug":"cve-2026-97185-a-flaw-was-found-in-gimp-when-processing-a-specially-crafted","title":"GIMP out-of-bounds write in GIMPressionist plugin","severity":"high","exploited":false,"published_at":"2026-09-24T09:17:08.937+00:00","url":"https://junglewise.ai/threats/cve-2026-97185-a-flaw-was-found-in-gimp-when-processing-a-specially-crafted"},{"cve":"CVE-2026-96889","cvss":7.8,"epss":0.0013,"slug":"cve-2026-96889-a-flaw-was-found-in-librsvg-when-processing-an-svg-document","title":"librsvg use-after-free in XML entity parsing","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:27.587+00:00","url":"https://junglewise.ai/threats/cve-2026-96889-a-flaw-was-found-in-librsvg-when-processing-an-svg-document"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Gnome Libsoup","slug":"libsoup","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/libsoup"},{"name":"Gnome GLib","slug":"glib","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/glib"},{"name":"Gnome Libxslt","slug":"libxslt","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/libxslt"},{"name":"Gnome Gdk-Pixbuf","slug":"gdk-pixbuf","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/gdk-pixbuf"},{"name":"Gnome Gvfs","slug":"gvfs","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/gvfs"},{"name":"Gnome Localsearch","slug":"localsearch","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/localsearch"},{"name":"Gnome Glib-Networking","slug":"glib-networking","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/glib-networking"}]}