Critical Heap Buffer Overflow in GIMP PSP File Parsing Allows Remote Code Execution
A heap-based buffer overflow vulnerability in GIMP's PSP file parsing (CVE-2026-4153) could allow remote attackers to execute arbitrary code when a user opens a malicious PSP file. The flaw, disclosed by Zero Day Initiative as ZDI-26-220, carries a CVSS score of 7.8 and has been patched by the GIMP project.