CVE-2026-54626Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-16: 1Patch / Workaround · 2026-06-16: 1Technical Details · 2026-06-16: 106-16
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Sigreturn Labs@sigreturn_labs
    Disclosure

    we found two new critical vulnerabilities in SAIL, the image decoding library: - CVE-2026-54626 (TGA decoder) - CVE-2026-54627 (PSD decoder) both heap out-of-bounds writes (CVSS 9.8). responsibly disclosed and now fixed, thanks to the quick reaction of the maintainers.

    Post summary

    Two critical heap OOB vulnerabilities (CVE‑2026‑54626, CVE‑2026‑54627) were discovered in the SAIL image decoder, rated CVSS 9.8, and have been responsibly disclosed and patched by the maintainers.

    01064877
    28 followersView on X

Explore more