Sail maintains a focused product line centered on its core platform, which despite limited breadth holds prominent standing in its operational domain. Vulnerabilities affecting this vendor skew toward critical severity and recur through memory-safety weakness classes including integer overflows that cascade to buffer overflows and heap-based buffer overflows, reflecting the low-level systems nature of the product. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sail over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27168CRITICAL SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. All versions are vulnerable to Heap-based Buffer Overflow thr | Feb 21, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-53510HIGH A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .psd file, an integer o | Aug 25, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-53085HIGH A memory corruption vulnerability exists in the PSD RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially crafted | Aug 25, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-52930HIGH A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a specially craft | Aug 25, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-52456HIGH A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .webp animation an int | Aug 25, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-50129HIGH A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a specially crafted .t | Aug 25, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-46407HIGH A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .bmp file, an integ | Aug 25, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-35984HIGH A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a specially crafted .p | Aug 25, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-32468HIGH A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .bmp file, an integer | Aug 25, 2025 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sail.
Media articles that mention a CVE ID that affects a product developed by Sail — matched by CVE ID, not by vendor name.