Giflib Project: community verdicts
2 notable / known-exploited Giflib Project CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Giflib Project CVE, see NVD ↗.
- CVE-2026-26740HIGH 8.2Real · low riskEPSS 1%
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.
- CVE-2026-23868MED 5.1EPSS 0%
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.