CVE-2026-59088

Source
https://cve.org/CVERecord?id=CVE-2026-59088
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59088.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-59088
Downstream
Related
Published
2026-08-10T10:53:03Z
Modified
2026-09-10T03:47:57Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Gimp: gimp: denial of service via signed integer overflow in fli file processing
Details

A flaw was found in GIMP. A signed integer overflow vulnerability exists in the file-fli plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the multiplication of image width and height can exceed the maximum integer value. A remote attacker could exploit this by tricking a user into opening a specially crafted FLI file, leading to the application crashing and resulting in a denial of service.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59088.json"
}
References

Affected packages

Git / github.com/gnome/gimp

Affected ranges

Type
GIT
Repo
https://github.com/gnome/gimp
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:gimp:gimp:3.2.4:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.2.4"
        },
        {
            "last_affected": "3.2.4"
        }
    ],
    "source": "CPE_STRING"
}
Type
GIT
Repo
https://gitlab.gnome.org/gnome/gimp
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:gimp:gimp:3.2.4:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.2.4"
        },
        {
            "last_affected": "3.2.4"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

3.*
3.2.4
Other
GIMP_3_2_4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59088.json"