do_layer_surface of the file src/IMG_xcf.c of the component XCF Image Parser. The manipulation leads to out-of-bounds read.This vulnerability is listed as CVE-2026-35444. The attack may be initiated remotely. There is no available exploit.
It is recommended to apply a patch to fix this issue.
SOCIAL SHARE CARD GENERATOR