VYPR

rpm package

opensuse/kitty&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/kitty&distro=openSUSE%20Leap%2016.0

Vulnerabilities (6)

  • CVE-2026-46604HigJun 26, 2026
    affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1

    The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.

  • CVE-2026-54057HigJun 12, 2026
    affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1

    Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version 0.47.3 fixes the issue.

  • CVE-2026-42851HigJun 12, 2026
    affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1

    Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered in `less`, an issue body in a TUI, etc. — can cause kitty to e

  • CVE-2026-42850HigJun 12, 2026
    affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1

    Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will make kitty return an error, this error is not escaped and will be correctly echoed back to the terminal

  • CVE-2026-33642CriMay 19, 2026
    affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1

    Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Hea

  • CVE-2026-33633HigMay 19, 2026
    affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1

    Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol