SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81893

MEDIUM · CVSS 4.7 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in gdk-pixbuf that affects applications processing specially crafted JPEG images with chunked ICC profile markers, leading to potential out-of-bounds writes due to stale metadata after buffer deallocation. This flaw can result in application crashes, making it critical for developers and organizations utilizing gdk-pixbuf version 2.26.4 or higher to prioritize patching and mitigating this risk. Users of image processing applications relying on gdk-pixbuf should also be vigilant against potential exploitation through malicious JPEG files.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81893
Severity
MEDIUM
CVSS
4.7
EPSS
0.11%

Original NVD Description

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4