CVE-2026-2049Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28618.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-131

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-18); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-18: 1Mentions · 2026-04-20: 1Technical Details · 2026-03-18: 103-1804-20
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-181
Disclosure1
2026-04-201
General1
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    General

    HDR images can pwn your SUSE server via GEGL (CVE-2026-2049 style). Instead of waiting for patches, learn to audit image parsers for good. Read more: 👉 https://tinyurl.com/3tuvc47p #SUSE https://t.co/0TAuT92uS5

    Post summary

    The tweet merely states that HDR images can exploit a GEGL vulnerability on SUSE servers and advises auditing image parsers, but it provides no technical details, PoC, or evidence of active exploitation.

    1000047
    1.5K followersView on X
  • Anonymous Tech@Anonymous_Tech7
    Disclosure

    GIMP installations are vulnerable to remote code execution via a heap-based buffer overflow in HDR file parsing, assigned CVE-2026-2049, with a CVSS rating of 7.8, exploiting user interaction with malicious files or pages.

    Post summary

    GIMP is vulnerable to remote code execution through a heap-based buffer overflow in HDR file parsing (CVE‑2026‑2049) with a CVSS score of 7.8, requiring user interaction with malicious files or pages.

    0000024
    1 followersView on X

Explore more