CVE-2026-42144: Greyclab Cimg

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted PNM/PGM/PPM file with large dimension values causes the overflow to wrap around, allocating an undersized buffer and potentially triggering a heap buffer overflow. Any application using CImg to load untrusted image files is affected. This issue has been patched via commit 4ca26bc.

Affected products

  • Greyclab Cimg: before 4ca26bce4d8c61fcd1507d5f9401b9fb1222c27d (fixed in 4ca26bce4d8c61fcd1507d5f9401b9fb1222c27d)

Published 2026-05-04. Last modified 2026-06-17.