CVE-2026-40493General

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999eca3bc979, the PSD codec computes bytes-per-pixel (`bpp`) from raw header fields `channels * depth`, but the pixel buffer is allocated based on the resolved pixel format. For LAB mode with `channels=3, depth=16`, `bpp = (3*16+7)/8 = 6`, but the format `BPP40_CIE_LAB` allocates only 5 bytes per pixel. Every pixel write overshoots, causing a deterministic heap buffer overflow on every row. Commit c930284445ea3ff94451ccd7a57c999eca3bc979 contains a patch.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-18); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-04-18: 3Mentions · 2026-04-19: 1Mentions · 2026-04-20: 2Mentions · 2026-04-21: 1Active Exploitation · 2026-04-18: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-18: 2Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 2Technical Details · 2026-04-21: 104-1804-1904-2004-21
Signal classification4 categories
General
228.6%
Patch
228.6%
Disclosure
228.6%
Active Exploitation
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-183
Active Exploitation1General2
2026-04-191
Patch1
2026-04-202
Disclosure2
2026-04-211
Patch1
Full discourse7 posts
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-40493 is a critical heap buffer overflow in SAIL’s PSD codec. A crafted LAB/16-bit PSD can trigger memory corruption and possible RCE. Assessment: Tier 2 — mitigate and patch. Full assessment: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-04-19/TIER_2_CVE-2026-40493.md #CVE #CyberSecurity #AppSec

    Post summary

    The tweet announces CVE‑2026‑40493—a critical heap buffer overflow in SAIL’s PSD codec, provides a brief technical overview, and directs readers to a detailed assessment recommending mitigation and patching.

    0001192
    45 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🔒 CVE-2026-40493 — SAIL’s PSD codec has a deterministic heap buffer overflow that can trigger during image parsing. If you ship or depend on affected Linux packages, verify the fix path now. Source: https://security-tracker.debian.org/tracker/CVE-2026-40493

    Post summary

    CVE‑2026‑40493 is a deterministic heap buffer overflow in a Linux PSD codec, and a patch or fix path is available for affected packages.

    0001027
    1.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40493: SAIL has heap buffer overflow in... Math kills: PSD decoder miscalculates LAB 16-bit bpp as 6 bytes but allocates 5, triggering deterministic heap overflow... https://zerodaysignal.com/vulnerability/CVE-2026-40493 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses a deterministic heap buffer overflow in the SAIL PSD decoder caused by a miscalculated LAB 16‑bit bpp. No PoC, exploit, or mitigation information is provided.

    0000088
    218 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Image codecs and library pipelines (CVSS 9.1-9.8) Affected: SAIL; NovumOS; Hot Chocolate Internet-facing exposure dominates, led by image codecs and runtime libraries; fixes and mitigations below. • CVE-2026-40492 (CVSS 9.8) In SAIL, the XWD codec can read/write beyond the allocated buffer when pixmap_depth is 8 and bits_per_pixel is 32, prior to patch 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02; patched in commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02. • CVE-2026-40493 (CVSS 9.8) In SAIL, the PSD codec computes bytes-per-pixel from channels and depth but allocates the buffer differently, causing a heap overflow in LAB mode (channels=3, depth=16); patched in commit c930284445ea3ff94451ccd7a57c999eca3bc979. • CVE-2026-40494 (CVSS 9.8) In SAIL, the TGA codec's raw-packet path lacks an equivalent bounds check, allowing writes past the end of a heap buffer; patched in commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302. • CVE-2026-40317 (CVSS 9.3) NovumOS allows JumpToUser to transfer control to kernel addresses from user space in versions prior to 0.24; fixed in 0.24. • CVE-2026-40324 (CVSS 9.1) Hot Chocolate Utf8GraphQLParser has no recursion depth limit, enabling deeply nested payloads to trigger stack overflow; MaxAllowedRecursionDepth added and enforced across recursive parser methods, with fixes in 12.22.7, 13.9.16, 14.3.1, and 15.1.14. 🛠️ Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (memory corruption paths, file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post lists several critical image codec and library CVEs with precise technical details, highlights the required patches and mitigations, and urges immediate remediation and detection.

    0000072
    99 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40493 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999… https://www.cve.org/CVERecord?id=CVE-2026-40493

    Post summary

    The post merely mentions the CVE and a commit hash without providing evidence for exploitation, mitigation, or technical details.

    0000059
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40493 Heap Buffer Overflow in SAIL PSD Codec LAB Mode Image Processing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40493

    Post summary

    A brief description of CVE-2026-40493 noting a heap buffer overflow in SAIL PSD Codec, with no additional details on PoC, exploitation, or patch.

    0000047
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    🚨 CRITICAL — CVE-2026-40493 SAIL is a cross-platform library for loading and saving ima… CVSS 9.8 ⚡ Exploit in the wild 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-40493 #Meta #CyberSecurity #InfoSec

    Post summary

    The post announces CVE‑2026‑40493 as critical, reports that it is being exploited in the wild, and notes no patch is available.

    000002
    145 followersView on X

Explore more