Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handlecomposecommand() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Heap Buffer Over-Read/Write. An attacker who can write escape sequences to a kitty terminal (e.g., via a malicious file, SSH login banner, or piped content) can supply crafted xoffset/yoffset values that pass the bounds check after wrapping but cause massive out-of-bounds heap memory access in compose_rectangles(). No user interaction is required. No non-default configuration is required. The attacker only needs the ability to produce output in a kitty terminal window. This issue has been fixed in version 0.47.0.
{
"cwe_ids": [
"CWE-125",
"CWE-190",
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33642.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:kovidgoyal:kitty:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.47.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-08-12T15:33:28Z"
[
{
"id": "CVE-2026-33642-82a3527e",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 2849.0,
"function_hash": "280457416764156885754909861011681358664"
},
"source": "https://github.com/kovidgoyal/kitty/commit/e9661f0f3afb4e4dbffa509adfb3df3c9780ad34",
"target": {
"function": "handle_compose_command",
"file": "kitty/graphics.c"
}
},
{
"id": "CVE-2026-33642-dc1e4042",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"280709711047299294137574032014209459525",
"85346557336307736872440387771568660609",
"170879151890253140071227728881778440264",
"317350391922474406785069908614255195877",
"133081243175796015896384702204921414521",
"236223751530012832227288039874492638852"
]
},
"source": "https://github.com/kovidgoyal/kitty/commit/e9661f0f3afb4e4dbffa509adfb3df3c9780ad34",
"target": {
"file": "kitty/graphics.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33642.json"