A flaw was found in GIMP. The XCF loader processes image-simulation-intent and image-simulation-bpc parasites without ensuring the parasite data is… (CVE-2026-108093)
Description
A vulnerability in GIMP's XCF loader allows a NULL pointer dereference when processing certain image parasites without verifying their presence. This can cause the application to crash when opening a specially crafted XCF file containing a zero-size simulation parasite. The issue impacts application availability but does not affect confidentiality or integrity.
CVSS v3.1
Score 5.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in GIMP involves the XCF loader processing the image-simulation-intent and image-simulation-bpc parasites without checking if the parasite data is present before dereferencing it. This leads to a NULL pointer dereference and application crash when opening a crafted XCF file with a zero-size simulation parasite. The CVSS 3.1 base score is 5.5, reflecting a medium severity with local attack vector, low complexity, no privileges required, user interaction needed, and impact limited to availability.
Potential Impact
Exploitation of this flaw results in a denial-of-service condition by crashing the GIMP application. There is no impact on confidentiality or integrity. The attack requires local access and user interaction to open a malicious file.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid opening untrusted or suspicious XCF files to prevent application crashes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h6qg-qj72-qh79
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-108093"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac96e572cdf04f65689a7f4
Added to database: 10/09/2026, 22:44:39 UTC
Last enriched: 10/09/2026, 22:51:25 UTC
Last updated: 10/10/2026, 03:48:07 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.