CVE-2026-26740 is a high-severity buffer overflow vulnerability (CVSS 8.2) found in giflib v.5.2.2, specifically within the EGifGCBToExtension function of the giflib_project giflib library. This flaw allows an unauthenticated remote attacker to trigger a denial of service by providing specially crafted input that overwrites an existing Graphic Control Extension block due to a lack of size validation. While the potential impact is a denial of service, there is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.2CPE matchmatch criteria | cpe:2.3:a:giflib_project:giflib:5.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.