CVEs affecting projects tracked on Release Alert, from NVD & OSV.
CVE-2026-40916 — MEDIUM severity vulnerability | Release Alert
CVE-2026-40916
5
MEDIUMCVSS v3
Published
April 15, 2026
Affected
3 projects
Assigned by
Red Hat
Severity scale
010
Description
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-length array.
ChocolateyGIMP is a multi-platform photo manipulation tool. GIMP is an acronym for GNU Image Manipulation Program. The GIMP is suitable for a variety of image manipulation tasks, including photo retouching, image composition, and image construction.It can be used as a simple paint program, an expert quality photo retouching program, an online batch processing system, a mass production image renderer, an image format converter, etc.
GIMP is expandable and extensible. It is designed to be augmented with plug-ins and extensions to do just about anything. The advanced scripting interface allows everything from the simplest task to the most complex image manipulation procedures to be easily scripted.
## Features
- High Quality Photo Manipulation: retouching, restoring to creative composites etc.
- Original Artwork Creation: power and flexibility to transform images into unique creations.
- Graphic Design Elements: gIMP is used for producing icons, graphical design elements, and art for user interface components and mockups.
- Programming Algorithms: high quality framework for scripted image manipulation, with multi-language support such as C, C++, Perl, Python, Scheme, and more
- Desktop Publishing Workflow: color management features to ensure high-fidelity color reproduction across digital and printed media.
- [More features...](https://www.gimp.org/features)

## Notes
- **If the package is out of date please check [Version History](#versionhistory) for the latest submitted version. If you have a question, please ask it in [Chocolatey Community Package Discussions](https://github.com/chocolatey-community/chocolatey-packages/discussions) or raise an issue on the [Chocolatey Community Packages Repository](https://github.com/chocolatey-community/chocolatey-packages/issues) if you have problems with the package. Disqus comments will generally not be responded to.**