CVE-2026-11526: GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
Published Jun 14, 2026
·Updated
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in makefilehandle.
Affected Software
2 affected componentsFixes available
CPAN GD<2.86
debian/libgd-perl<=2.73-1, <=2.76-4, <=2.78-1
2.73-1+deb11u12.76-4+deb12u12.78-1+deb13u12.84-3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libgd-perlto a version that resolves this vulnerability.Fixed in 2.73-1+deb11u1Fixed in 2.76-4+deb12u1Fixed in 2.78-1+deb13u1Fixed in 2.84-3 - Upgrade
Upgrade
GD (Perl)to a version that resolves this vulnerability.Fixed in 2.86
Event History
Jun 14, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
RemedyDescriptionWeakness
Data Sourced
via Red Hat·12:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Jul 1, 2026
Data Sourced
via Ubuntu·01:06 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·01:07 PM
DescriptionAffected Software
Data Sourced
via Launchpad·01:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-11526?
CVE-2026-11526 has a risk rating of 76, indicating a high severity level.
2
How do I fix CVE-2026-11526?
To mitigate CVE-2026-11526, update GD for Perl to version 2.86 or later.
3
What type of vulnerabilities does CVE-2026-11526 include?
CVE-2026-11526 includes OS command injection and file overwrite vulnerabilities.
4
Which software is affected by CVE-2026-11526?
CVE-2026-11526 affects GD versions prior to 2.86 for Perl.
5
How does CVE-2026-11526 allow for exploitation?
CVE-2026-11526 allows exploitation via a two-argument open() function that accepts manipulated filename arguments.