CVE-2026-59091
Received Received - Intake

GIMP PSD and PAA File Format Plugin Vulnerabilities

Vulnerability report for CVE-2026-59091, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Red Hat, Inc.

Description

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnome gimp *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in GIMP's file format plugins, such as those for PSD and PAA files. An attacker could exploit it by convincing a user to open a specially crafted image file, leading to unexpected behavior or security issues without additional user interaction.

Detection Guidance

Detecting this vulnerability requires monitoring for suspicious image files or unusual application behavior. Check GIMP logs for crashes or errors when opening PSD or PAA files. Inspect network traffic for unexpected file transfers involving these formats.

Impact Analysis

If exploited, this vulnerability could allow an attacker to execute arbitrary code or cause denial-of-service conditions on your system. It may also lead to unauthorized access to sensitive data or system compromise, depending on the attacker's goals.

Compliance Impact

The vulnerability could lead to unauthorized access or manipulation of image files, potentially exposing sensitive data. This may impact compliance with GDPR (data protection) or HIPAA (health information privacy) if exploited to access protected content.

Mitigation Strategies

Update GIMP to the latest version to patch the flaw. Avoid opening untrusted PSD or PAA files. Use antivirus tools to scan suspicious files before opening. Disable unnecessary GIMP plugins if updates are delayed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59091. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart