CVE-2026-94287: X.org Libxpm

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.

Affected products

  • X.org Libxpm: before 3.5.19 (fixed in 3.5.19)

Published 2026-09-28. Last modified 2026-09-29.