CVE-2026-40492Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, the XWD codec resolves pixel format based on `pixmap_depth` but the byte-swap code uses `bits_per_pixel` independently. When `pixmap_depth=8` (BPP8_INDEXED, 1 byte/pixel buffer) but `bits_per_pixel=32`, the byte-swap loop accesses memory as `uint32_t*`, reading/writing 4x the allocated buffer size. This is a different vulnerability from the previously reported GHSA-3g38-x2pj-mv55 (CVE-2026-27168), which addressed `bytes_per_line` validation. Commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02 contains a patch.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-18); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-18: 3Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Active Exploitation · 2026-04-18: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-18: 2Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 104-1804-1904-20
Signal classification3 categories
Disclosure
360.0%
Active Exploitation
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-183
Active Exploitation1Disclosure2
2026-04-191
Patch1
2026-04-201
Disclosure1
Full discourse5 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40492: SAIL has heap buffer overflow in... Type confusion between pixmap_depth and bits_per_pixel creates 4x heap overflow in XWD decoder—trivial to trigger, perf... https://zerodaysignal.com/vulnerability/CVE-2026-40492 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-40492, detailing a trivial-to-trigger 4x heap buffer overflow caused by type confusion in the XWD decoder; no exploitation, PoC, patch, or false‑positive claim is mentioned.

    0000075
    218 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Image codecs and library pipelines (CVSS 9.1-9.8) Affected: SAIL; NovumOS; Hot Chocolate Internet-facing exposure dominates, led by image codecs and runtime libraries; fixes and mitigations below. • CVE-2026-40492 (CVSS 9.8) In SAIL, the XWD codec can read/write beyond the allocated buffer when pixmap_depth is 8 and bits_per_pixel is 32, prior to patch 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02; patched in commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02. • CVE-2026-40493 (CVSS 9.8) In SAIL, the PSD codec computes bytes-per-pixel from channels and depth but allocates the buffer differently, causing a heap overflow in LAB mode (channels=3, depth=16); patched in commit c930284445ea3ff94451ccd7a57c999eca3bc979. • CVE-2026-40494 (CVSS 9.8) In SAIL, the TGA codec's raw-packet path lacks an equivalent bounds check, allowing writes past the end of a heap buffer; patched in commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302. • CVE-2026-40317 (CVSS 9.3) NovumOS allows JumpToUser to transfer control to kernel addresses from user space in versions prior to 0.24; fixed in 0.24. • CVE-2026-40324 (CVSS 9.1) Hot Chocolate Utf8GraphQLParser has no recursion depth limit, enabling deeply nested payloads to trigger stack overflow; MaxAllowedRecursionDepth added and enforced across recursive parser methods, with fixes in 12.22.7, 13.9.16, 14.3.1, and 15.1.14. 🛠️ Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (memory corruption paths, file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The message announces several high‑severity CVEs in image codecs and libraries, provides detailed technical information, and offers specific patch and mitigation guidance.

    0000072
    99 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40492 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f… https://www.cve.org/CVERecord?id=CVE-2026-40492

    Post summary

    The tweet announces CVE‑2026‑40492 for the SAIL image library, providing only the CVE reference and no further technical or remediation details.

    00000109
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40492 Buffer Over-Read in SAIL XWD Codec Due to Mismatched Pixel Format Validation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40492

    Post summary

    The entry announces CVE-2026-40492 as a buffer over‑read flaw in the SAIL XWD codec, but provides no exploit, patch, or active‑use information.

    0000044
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    🚨 CRITICAL — CVE-2026-40492 SAIL is a cross-platform library for loading and saving ima… CVSS 9.8 ⚡ Exploit in the wild 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-40492 #Meta #CyberSecurity #InfoSec

    Post summary

    CVE‑2026‑40492 is a critical flaw in the SAIL library with a CVSS score of 9.8, actively exploited in the wild and currently unpatched.

    000002
    145 followersView on X

Explore more