OVERVIEW CVE-2026-33023 is a use-after-free vulnerability in libsixel versions 1.8.7 and earlier that occurs in the load_with_gdkpixbuf() function when the library is compiled with gdk-pixbuf2 support. The vulnerability stems from inconsistent memory cleanup practices: while the builtin loader properly uses reference-counted destruction, the gdk-pixbuf2 variant manually frees objects without checking reference counts, leaving dangling pointers when callers retain references to the frame object. This affects any application built against libsixel with gdk-pixbuf2 support. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a local attack vector requiring user interaction but no special privileges. The attack complexity is low, meaning exploitation is straightforward. An attacker can reliably trigger the use-after-free by supplying a crafted image file, potentially achieving information disclosure, memory corruption, or arbitrary code execution depending on the affected application's context and memory layout. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed on the Known Exploited Vulnerabilities catalog, and exploit code availability is not documented in public sources. The FAUCET risk score of 49/100 and exceptionally low EPSS score of 0.00006 suggest minimal community attention and exploitation interest to date. The issue was patched in version 1.8.7-r1, and organizations should prioritize updates for applications using libsixel with gdk-pixbuf2 support.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.7CPE matchmatch criteria | cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.