Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-2045

30
FAUCET Score

CVE-2026-2045 is an out-of-bounds write vulnerability in GIMP's XWD file parsing, allowing remote code execution. It affects GIMP installations and requires user interaction, such as opening a malicious file, to exploit. With a CVSS score of 7.8 (High), this flaw can lead to complete compromise of confidentiality, integrity, and availability. While no public exploits or Metasploit modules are currently available, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.

Impacted Technologies

VendorProductVersion(s)CPE
3.0.6CPE matchmatch criteria
cpe:2.3:a:gimp:gimp:3.0.6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.8HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
4.64%
Probability of exploitation in next 30 days
EPSS Percentile
90.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0464 is in the 97th percentile among its peer group of 759 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gimp:2.8/gimp
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: gimp

Vendor Advisories (1)

redhatCVE-2026-2045Important

gimp: GIMP: Remote Code Execution via out-of-bounds write in XWD file parsing

Feb 20, 2026

References

access.redhat.com / errata/RHSA-2026:4173
access.redhat.com / errata/RHSA-2026:5113
access.redhat.com / errata/RHSA-2026:5388
access.redhat.com / errata/RHSA-2026:5389
access.redhat.com / errata/RHSA-2026:5390
access.redhat.com / errata/RHSA-2026:5391
access.redhat.com / errata/RHSA-2026:5434
access.redhat.com / errata/RHSA-2026:5435
access.redhat.com / errata/RHSA-2026:5436
access.redhat.com / errata/RHSA-2026:5437
access.redhat.com / security/cve/CVE-2026-2045
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-2045.json
gitlab.gnome.org / GNOME/gimp/-/commit/68b27dfb1cbd9b3f22d7fa624dbab8647ee5f275
Issue TrackingPatchThird Party Advisory
zerodayinitiative.com / advisories/ZDI-26-119
Third Party Advisory