CVE-2026-79902: Gimp

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.

Affected products

  • Gimp Gimp: up to and including 3.3.1

Published 2026-08-26. Last modified 2026-09-01.