ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92183.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Because user interaction is required (victim must visit a malicious page or open a malicious file), reduce exposure by restricting users from opening untrusted files and limiting browsing to trusted sources; additionally, use email/web filtering to block malicious APNG/file delivery.
- Compensating control
Apply the ZDI-referenced mitigation guidance for ZDI-26-713 (GIMP APNG File Parsing Stack-based Buffer Overflow / Remote Code Execution) for deployments of GIMP, since the material does not specify a fixed GIMP version or patch KB number.