MEDIUMVulnerability

CVE-2026-79902

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.

Properties

severity
MEDIUM
score
5.5
epss_score
0.00201
cve_id
CVE-2026-79902
vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
published_at
2026-08-26T14:17:16.430
last_modified
2026-09-01T14:18:08.680
epss_percentile
0.09969

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Integer Overflow or Wraparound

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-79902 — Ninja Signal Threat Intelligence | Ninja Signal