CVE-2026-40494Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302, the TGA codec's RLE decoder in `tga.c` has an asymmetric bounds check vulnerability. The run-packet path (line 297) correctly clamps the repeat count to the remaining buffer space, but the raw-packet path (line 305-311) has no equivalent bounds check. This allows writing up to 496 bytes of attacker-controlled data past the end of a heap buffer. Commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302 patches the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-18); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-18: 3Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Active Exploitation · 2026-04-18: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-18: 2Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 104-1804-1904-20
Signal classification3 categories
Disclosure
360.0%
Active Exploitation
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-183
Active Exploitation1Disclosure1General1
2026-04-191
Disclosure1
2026-04-201
Disclosure1
Full discourse5 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40494: SAIL has heap buffer overflow in... Asymmetric bounds checking in SAIL's TGA RLE decoder lets attackers heap spray 496 bytes past buffer end via crafted ra... https://zerodaysignal.com/vulnerability/CVE-2026-40494 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text announces CVE-2026-40494, detailing a heap buffer overflow in SAIL’s TGA RLE decoder that permits a 496‑byte heap spray, but provides no PoC, exploit code, or patch information.

    00000140
    218 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 Critical CVEs Today: Image codecs and library pipelines (CVSS 9.1-9.8) Affected: SAIL; NovumOS; Hot Chocolate Internet-facing exposure dominates, led by image codecs and runtime libraries; fixes and mitigations below. • CVE-2026-40492 (CVSS 9.8) In SAIL, the XWD codec can read/write beyond the allocated buffer when pixmap_depth is 8 and bits_per_pixel is 32, prior to patch 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02; patched in commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02. • CVE-2026-40493 (CVSS 9.8) In SAIL, the PSD codec computes bytes-per-pixel from channels and depth but allocates the buffer differently, causing a heap overflow in LAB mode (channels=3, depth=16); patched in commit c930284445ea3ff94451ccd7a57c999eca3bc979. • CVE-2026-40494 (CVSS 9.8) In SAIL, the TGA codec's raw-packet path lacks an equivalent bounds check, allowing writes past the end of a heap buffer; patched in commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302. • CVE-2026-40317 (CVSS 9.3) NovumOS allows JumpToUser to transfer control to kernel addresses from user space in versions prior to 0.24; fixed in 0.24. • CVE-2026-40324 (CVSS 9.1) Hot Chocolate Utf8GraphQLParser has no recursion depth limit, enabling deeply nested payloads to trigger stack overflow; MaxAllowedRecursionDepth added and enforced across recursive parser methods, with fixes in 12.22.7, 13.9.16, 14.3.1, and 15.1.14. 🛠️ Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (memory corruption paths, file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post is a technical disclosure of multiple high‑CVSS CVEs, providing detailed vulnerability mechanisms and patch information.

    0000072
    99 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40494 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 45d48d1f2e8e0d73e80bc1fd5310cb5… https://www.cve.org/CVERecord?id=CVE-2026-40494

    Post summary

    The brief snippet references CVE-2026-40494 and a specific commit but provides no technical details, patch information, or exploitation evidence.

    0000059
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40494 Buffer Overflow in SAIL TGA Codec RLE Decoder Raw-Packet Path https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40494

    Post summary

    The memo announces CVE-2026-40494, noting a buffer overflow in the SAIL TGA codec’s RLE decoder, and links to a vulnerability detail page without providing PoC, exploit, or patch information.

    0000049
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    🚨 CRITICAL — CVE-2026-40494 SAIL is a cross-platform library for loading and saving ima… CVSS 9.8 ⚡ Exploit in the wild 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-40494 #Meta #CyberSecurity #InfoSec

    Post summary

    CVE-2026-40494 is a critical vulnerability (CVSS 9.8) that is being actively exploited in the wild, with no patch currently available.

    000002
    124 followersView on X

Explore more