CVE-2026-23868 describes a double-free vulnerability within Giflib, stemming from a shallow copy in GifMakeSavedImage and improper error handling. While the specific affected products are not detailed, the conditions required to trigger this flaw are considered difficult to achieve. There is no CVSS score, EPSS, or FAUCET Risk Score provided, and no known exploit intelligence, active exploitation, or community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, <= 6.1.1CPE matchmatch criteria | cpe:2.3:a:giflib_project:giflib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
GIFLIB vulnerabilities
Jul 22, 2026Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.
Mar 10, 2026