CVE-2026-108093
MEDIUM
NVD
CVSS Score
5.5
Severity
MEDIUM
Published
Oct 09, 2026
Vendor
unknown
Description
A flaw was found in GIMP. The XCF loader processes image-simulation-intent and image-simulation-bpc parasites without ensuring the parasite data is present before dereferencing it. Opening a specially crafted XCF file with a zero-size simulation parasite can cause a NULL pointer dereference and crash the GIMP application.