Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
7.3
CVE-2026-59091EXPLOITED
red hat · red hat enterprise linux

Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file

Description

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcegimpcert_advisory90%

References

  • https://access.redhat.com/security/cve/CVE-2026-59091(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2496585(issue-tracking, x_refsource_REDHAT)
  • https://gitlab.gnome.org/GNOME/gimp/-/work_items/16510

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [hoch] GIMP: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-59091 | Red Hat Enterprise Linux 6/7/8/9 PSD/PAA File Format Plugins buffer overflow
→ No new info (linked only)
CVSS 3.17.3 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-787
PublishedAug 10, 2026
Last enriched1d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score47
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-4480EXPKEV
Samba: samba: remote code execution in printing subsystem via unescaped job description
Trending: 49
MEDIUMCVE-2026-6426EXP
Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access
Trending: 45
NONECVE-2026-59090EXP
Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
Trending: 44
NONECVE-2026-63623EXP
Libvirt: information disclosure via world-readable storage volume images during clone/convert
Trending: 43
NONECVE-2026-59088EXP
Gimp: gimp: denial of service via signed integer overflow in fli file processing
Trending: 43

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026
Actively Exploited
Aug 11, 2026
Exploit Available
Aug 11, 2026