← Vulnerability feed

Vulnerability record · CVE-2026-27168 · published 21 February 2026

CVE-2026-27168: Sail heap-based buffer overflow vulnerability

Sail · Sail

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. All versions are vulnerable to Heap-based Buffer Overflow through the XWD parser's use of the bytes_per_line value. The value os read directly from the file as the read size in io->strict_read(), and is never compared to the actual size of the destination buffer. An attacker can provide an XWD file with an arbitrarily large bytes_per_line, causing a massive write operation beyond the buffer heap allocated for the image pixels. The issue did not have a fix at the time of publication.

9.8 CVSS 3.1 Critical EPSS 0.66% · top 50.3% CWE-122 · Heap-based buffer overflow
9.8CVSS 3.1 base score
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. All versions are vulnerable to Heap-based Buffer Overflow through the XWD parser's use of the bytes_per_line value. The value os read directly from the file as the read size in io->strict_read(), and is never compared to the actual size of the destination buffer. An attacker can provide an XWD file with an arbitrarily large bytes_per_line, causing a massive write operation beyond the buffer heap allocated for the image pixels. The issue did not have a fix at the time of publication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-27168 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-53510Sail vulnerabilityA memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially …EPSS 0.69%8.8CVE-2025-52456Sail vulnerabilityA memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially…EPSS 0.86%8.8CVE-2025-52930Sail vulnerabilityA memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the im…EPSS 0.93%8.8CVE-2025-53085Sail heap-based buffer overflow vulnerabilityA memory corruption vulnerability exists in the PSD RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the imag…EPSS 0.93%8.8CVE-2025-35984Sail heap-based buffer overflow vulnerabilityA memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image d…EPSS 1.4%8.8CVE-2025-46407Sail vulnerabilityA memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specia…EPSS 0.66%8.8CVE-2025-50129Sail heap-based buffer overflow vulnerabilityA memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image d…EPSS 0.93%8.8CVE-2025-32468Sail vulnerabilityA memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a speciall…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2026-27168), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.