CVE-2026-6695
Last modified
CVE-2026-6695 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | All versions |
| Red Hat | Red Hat Enterprise Linux 7 | All versions |
| Red Hat | Red Hat Enterprise Linux 8 | All versions |
| Red Hat | Red Hat Enterprise Linux 9 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-6695?
How severe is CVE-2026-6695?
How do I fix CVE-2026-6695?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66919Pivotick contains a cross-site scripting vulnerability in th…6.9
- CVE-2026-6692The Slider Revolution plugin for WordPress is vulnerable to …8.8
- CVE-2026-66920Pivotick contains an uncontrolled-recursion vulnerability wh…8.2
- CVE-2026-66921Pivotick’s Markdown node-reference renderer failed to HTML-e…6.3
- CVE-2026-66922Pivotick used plain JavaScript objects as lookup tables inde…5.1
- CVE-2026-6694A flaw was found in GIMP's file-png plugin. A remote attacke…5.5
- CVE-2026-6696The Zingaya Click-to-Call plugin for WordPress is vulnerable…6.1
- CVE-2026-6700The DX Sources plugin for WordPress is vulnerable to Cross-S…4.3
- CVE-2026-6701The addfreespace plugin for WordPress is vulnerable to Cross…4.3
- CVE-2026-6702The Publish 2 Ping.fm plugin for WordPress is vulnerable to …6.1
- CVE-2026-6703The Responsive Blocks – Page Builder for Blocks & Patterns p…4.3
- CVE-2026-6704The Blog Settings plugin for WordPress is vulnerable to Refl…6.1
Are you affected by CVE-2026-6695?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
