SEPTEMBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-82328

MEDIUM · CVSS 6.1 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

A vulnerability in the file-ico plugin of GIMP allows for improper validation of the palette count parameter when processing specially crafted ICO image files, leading to heap out-of-bounds reads. This flaw can cause application crashes, resulting in denial of service and potential disclosure of sensitive information from heap memory. Users and organizations utilizing GIMP, particularly those handling untrusted image files, should prioritize addressing this issue to mitigate risks.

CVE
CVE-2026-82328
Severity
MEDIUM
CVSS
6.1
EPSS
0.12%

Original NVD Description

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

Related CVEs

Other vulnerabilities affecting the same vendor(s)