Known Vulnerabilities for products from Gimp

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Gimp".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-80101 json Not Provided 2026-08-25 2026-08-25
CVE-2026-78475 json Not Provided 2026-08-24 2026-08-25
CVE-2026-78465 json Not Provided 2026-08-24 2026-08-25
CVE-2026-66759 json A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin ... Not Provided 2026-07-27 2026-08-24
CVE-2026-66758 json A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation ... Not Provided 2026-07-27 2026-08-07
CVE-2026-66757 json A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for... Not Provided 2026-07-27 2026-08-10
CVE-2026-59091 json A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these ... Not Provided 2026-08-10 2026-08-24
CVE-2026-59090 json Not Provided 2026-08-10 2026-08-21
CVE-2026-59089 json Not Provided 2026-07-06 2026-08-21
CVE-2026-59088 json A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image f... Not Provided 2026-08-10 2026-08-21
CVE-2026-59087 json A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote atta... Not Provided 2026-08-10 2026-08-24
CVE-2026-58384 json A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for ... Not Provided 2026-07-07 2026-07-16
CVE-2026-58380 json A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() funct... Not Provided 2026-07-06 2026-07-16
CVE-2026-40919 json A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when... Not Provided 2026-04-15 2026-04-28
CVE-2026-40918 json A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service... Not Provided 2026-04-15 2026-04-28
CVE-2026-40917 json A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing ... Not Provided 2026-04-15 2026-04-28
CVE-2026-40916 json A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local u... Not Provided 2026-04-15 2026-04-28
CVE-2026-40915 json A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by provi... Not Provided 2026-04-15 2026-04-28
CVE-2026-6695 json A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint... Not Provided 2026-08-03 2026-08-19
CVE-2026-6384 json A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function a... Not Provided 2026-04-15 2026-07-15

Known software with vulnerabilities from Gimp

Type Vendor Product Version
ApplicationGimpGimp-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report