CVE-2026-33633HIGH 8.8EPSS p25.7%

CVE-2026-33633CVE-2026-33633

Description

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a PNG format declaration (f=100) whose payload exceeds twice the initial buffer capacity. The overflow is attacker-controlled in both length and content, causing DoS and potentially escalation to RCE itself. This issue has been fixed in version 0.47.0.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.34% probability of exploitation · percentile 25.7% · 2026-06-19T12:03:05Z
Published2026-05-19
Last modified2026-05-22

Underlying weaknesses· 1

CWE-122

References

  1. https://github.com/kovidgoyal/kitty/commit/e9661f0f3afb4e4dbffa509adfb3df3c9780ad34
  2. https://github.com/kovidgoyal/kitty/security/advisories/GHSA-j68c-v8x4-269g
  3. https://github.com/kovidgoyal/kitty/security/advisories/GHSA-j68c-v8x4-269g

1

TypeTargetConfidenceTier
WeaknessHeap-based Buffer Overflowcwe-1220%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-33642
CVE
CVE-2026-33999
CVE
CVE-2026-26740
CVE
CVE-2026-34003
CVE
CVE-2026-42483
CVE
CVE-2026-34352
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.