
Sigreturn Labs@sigreturn_labs
Disclosure
we found two new critical vulnerabilities in SAIL, the image decoding library: - CVE-2026-54626 (TGA decoder) - CVE-2026-54627 (PSD decoder) both heap out-of-bounds writes (CVSS 9.8). responsibly disclosed and now fixed, thanks to the quick reaction of the maintainers.
Post summary
Two critical heap OOB vulnerabilities (CVE‑2026‑54626, CVE‑2026‑54627) were discovered in the SAIL image decoder, rated CVSS 9.8, and have been responsibly disclosed and patched by the maintainers.
01064877
28 followersView on X
