
🔴 Vikunja, WebSocket Session Revocation Bypass, #CVE-2026-78465 (Critical) -DC-Oct2026-3055 https://dailycve.com/vikunja-websocket-session-revocation-bypass-cve-2026-78465-critical-dc-oct2026-3055/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

🔴 Vikunja, WebSocket Session Revocation Bypass, #CVE-2026-78465 (Critical) -DC-Oct2026-3055 https://dailycve.com/vikunja-websocket-session-revocation-bypass-cve-2026-78465-critical-dc-oct2026-3055/
2 of 2 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | gimp | gimp | - | - | - |
| App | gimp | gimp | 3.3.1 | - | - |