CVE-2026-33642Disclosure(kovidgoyal / kitty)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch kovidgoyal kitty systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Heap Buffer Over-Read/Write. An attacker who can write escape sequences to a kitty terminal (e.g., via a malicious file, SSH login banner, or piped content) can supply crafted x_offset/y_offset values that pass the bounds check after wrapping but cause massive out-of-bounds heap memory access in compose_rectangles(). No user interaction is required. No non-default configuration is required. The attacker only needs the ability to produce output in a kitty terminal window. This issue has been fixed in version 0.47.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-190CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kitty

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
kitty

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-19: 2Mentions · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-26: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-19: 2Technical Details · 2026-05-26: 105-1905-26
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-192
Disclosure1General1
2026-05-261
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33642 Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on co… https://www.cve.org/CVERecord?id=CVE-2026-33642

    Post summary

    The post discloses a bounds-validation flaw in Kitty terminal’s graphics.c, provides some technical detail about the vulnerable function but no PoC, exploit code, or patch information, and does not indicate active exploitation or a false positive.

    01010134
    57.5K followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Patch

    Yesterday's Kitty CVE-2026-33642 is a clean example. Heap overflow in the graphics escape handler. ≤0.46.2 vulnerable, 0.47.0 fixed. The kicker: an SSH banner can carry the exploit. So can the MOTD of a host you just connected to.

    Post summary

    The excerpt focuses on CVE‑2026‑33642 as a heap overflow in Kitty that can be triggered via SSH banner/MOTD, specifies the vulnerable and fixed versions, and thus highlights the availability of a patch.

    1000055
    35 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33642 Heap Buffer Over-Read/Write via Integer Wrapping in Kitty Terminal 0.46.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33642

    Post summary

    A heap buffer over‑read/write vulnerability in Kitty Terminal 0.46.2 is reported via integer wrapping, but no PoC, exploit, patch, active exploitation, or debunking claim is provided.

    0000056
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkovidgoyalkitty---

Explore more