CVE-2026-4887 identifies a medium-severity heap buffer over-read vulnerability within the GIMP PCX image file loader, caused by an off-by-one error. A remote attacker could exploit this flaw by convincing a user to open a specially crafted PCX image. Successful exploitation may lead to out-of-bounds memory disclosure and a high-impact denial of service through application crashes. There is currently no evidence of active exploitation, nor are public exploit codes available on platforms like Metasploit or ExploitDB. Community discussion and media coverage regarding this vulnerability are also absent at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.0CPE matchmatch criteria | cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:gimp:gimp:3.2.0:rc1:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:gimp:gimp:3.2.0:rc2:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:gimp:gimp:3.2.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.