Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-4151

gimp: GIMP: Remote Code Execution via ANI File Parsing Integer Overflow (important)
Back to all
CVE

CVE-2026-4151

gimp: GIMP: Remote Code Execution via ANI File Parsing Integer Overflow (important)

DOCUMENTATION: A flaw was found in GIMP. Remote attackers can exploit this vulnerability by tricking a user into opening a specially crafted ANI (Animated Cursor) file or visiting a malicious web page. This issue stems from an integer overflow during the parsing of ANI files, caused by insufficient validation of user-supplied data before memory allocation. Successful exploitation could allow an attacker to execute arbitrary code on the affected system with the privileges of the current user. 

            STATEMENT: Important: This flaw in GIMP allows for remote code execution due to an integer overflow when parsing specially crafted ANI (Animated Cursor) files. Exploitation requires user interaction, specifically opening a malicious ANI file or visiting a malicious web page. Red Hat users are affected if they process untrusted ANI files with GIMP.

            MITIGATION: To mitigate this issue, users should exercise caution and avoid opening untrusted ANI (Animated Cursor) files or visiting untrusted web pages. This vulnerability relies on user interaction to trigger the flaw, therefore, refraining from interacting with untrusted content will prevent exploitation.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
7.8
-
3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
C
H
U
-
C
H
U
-

Related Resources

No items found.

References

https://access.redhat.com/security/cve/CVE-2026-4151

Severity

0

CVSS Score
0
10

Basic Information

Ecosystem
Base CVSS
0
EPSS Probability
0.0004%
EPSS Percentile
0.12554%
Introduced Version
0
Fix Available
2:3.0.4-1.el9_7.5,2:3.0.4-4.el9_8.4,3.0.4-3+deb13u8

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading