CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-4367

mediumCVSS 5.5covered by 3 sourcesfirst seen 2026-06-09
Naoki Wakamatsu discovered that libXpm did not properly validate file boundaries when processing XPM image files. An attacker could possibly use this issue to cause libXpm to crash, resulting in a denial of service.

CSIRTS triage

What
Improper validation of file boundaries can cause libXpm to crash.
Who is affected
Users of libXpm.
Urgency
Remediation is needed to avoid denial of service incidents.
Action
Update libXpm to a patched version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-4367

Get an email if CVE-2026-4367 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-4367

CVE.org record

Embed the live status

CVE-2026-4367 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-4367 status](https://www.csirts.com/badge/CVE-2026-4367)](https://www.csirts.com/cve/CVE-2026-4367)