OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-54626

CRITICAL · CVSS 9.8 EPSS 0.78% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the SAIL library versions 0.9.10 and earlier, specifically in the handling of color-mapped run-length-encoded TGA files, where an attacker can exploit a flaw in buffer allocation to write beyond the allocated heap pixel buffer. This can lead to heap corruption, crashes, or potentially arbitrary code execution. Organizations using this library for image processing, especially those handling untrusted image inputs, should prioritize upgrading to version 1.0.0 to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54626
Severity
CRITICAL
CVSS
9.8
EPSS
0.78%

Original NVD Description

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-byte-per-pixel SAIL_PIXEL_FORMAT_BPP8_INDEXED format returned by tga_private_sail_pixel_format() in src/sail-codecs/tga/helpers.c, while sail_codec_load_frame_v8_tga() in src/sail-codecs/tga/tga.c derives a two-to-four-byte pixel_size from an attacker-controlled header bpp value from 9 through 32. Loading a crafted color-mapped run-length-encoded TGA through sail_load_from_file() or sail_load_from_memory() therefore writes attacker-controlled bytes beyond the heap pixel buffer. The pixel-count clamp added for CVE-2026-40494 does not constrain the per-pixel write width, so this issue is an incomplete fix of that vulnerability and can cause heap corruption, a reliable crash, or potential code execution. This issue is fixed in version 1.0.0.