CVE-2026-9672
Malformed GIF files processed with GD extension lead to potential arbitrary code execution
| Publication Date | 2026-08-01 |
|---|---|
| Severity | High |
| Type | Remote Code Execution |
| Affected PHP Versions |
|
| Fixed Product Versions |
|
CVE Details
A vulnerability in libgd2 allows malformed GIF files to execute arbitrary code (RCE), potentially leading to a Denial of Service (DoS).
Recommendations
If you process GIF images using the GD extension in PHP, we recommend upgrading immediately to a version containing a patch.