CVE-2026-59091: Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file
A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction.
Other sources
A source-level audit of GIMP's file format plugins identified 2 vulnerabilities in default-install plugins (file-psd, file-paa). Both are triggerable by opening a crafted image file — no user interaction beyond "File > Open" is required. Each finding has been independently reproduced with a standalone PoC and confirmed via AddressSanitizer or arithmetic verification in a Docker environment (Fedora 41, gcc, zlib-devel).
https://gitlab.gnome.org/GNOME/gimp/-/workitems/16510
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59091?
CVE-2026-59091 has a high severity score of 7.3.
How can I mitigate the risks associated with CVE-2026-59091?
To mitigate CVE-2026-59091, avoid opening untrusted or suspicious image files in GIMP.
What types of file format plugins are affected by CVE-2026-59091?
CVE-2026-59091 affects multiple file format plugins in GIMP, specifically those for PSD and PAA files.
What are the potential impacts of exploiting CVE-2026-59091?
Exploiting CVE-2026-59091 can lead to unexpected application behavior and potential security issues.
Is there a fix available for CVE-2026-59091?
Yes, users should update to the latest version of GIMP where the vulnerabilities are addressed.