SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90949

HIGH · CVSS 7.8 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A heap-based buffer overflow vulnerability exists in GIMP's PSP file loader, which can be exploited by remote attackers through specially crafted PSP files. This flaw may lead to application crashes or arbitrary code execution, posing a significant risk to users of GIMP. Organizations utilizing GIMP should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90949
Severity
HIGH
CVSS
7.8
EPSS
N/A

Original NVD Description

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. A remote attacker could exploit this vulnerability by crafting a malicious PSP file. Opening this file in GIMP could lead to a crash or arbitrary code execution.