MEDIUMVulnerability
CVE-2026-79902
A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.
Properties
- severity
- MEDIUM
- score
- 5.5
- epss_score
- 0.00201
- cve_id
- CVE-2026-79902
- vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- published_at
- 2026-08-26T14:17:16.430
- last_modified
- 2026-09-01T14:18:08.680
- epss_percentile
- 0.09969
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (1)
→[Product]
HAS_WEAKNESS (1)
→[Weakness]Integer Overflow or Wraparound
Explore deeper with Ninja Signal's threat intelligence graph