CPANSA-GD-2026-11526: GD vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-06-14T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-06-14T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 9.8 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "cmd |") or begins with a redirect ("> path", ">> path") is run as a command or redirect rather than opened as a file. _make_filehandle is the single open path behind every filename-accepting constructor (new, newFromPng, newFromJpeg, and the rest); the in-memory *Data variants do not open a path and are unaffected. Any caller that forwards untrusted input to one of these constructors as a pathname can run an arbitrary command or truncate a file under the process UID.
Vulnerabilities
CVE-2026-11526
Vulnerability DescriptionGD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle.
GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "cmd |") or begins with a redirect ("> path", ">> path") is run as a command or redirect rather than opened as a file. _make_filehandle is the single open path behind every filename-accepting constructor (new, newFromPng, newFromJpeg, and the rest); the in-memory *Data variants do not open a path and are unaffected.
Any caller that forwards untrusted input to one of these constructors as a pathname can run an arbitrary command or truncate a file under the process UID.
| Weakness | CWE-73 : External Control of File Name or Path |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| GD less than 2.86 |
|
Fixed
- GD greater than or equal 2.86
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-GD-2026-11526 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-gd-2026-11526.json - https://github.com/lstein/Perl-GD/commit/67b163713c6c78dfeb693da0978ae934e5cd8210.patch external
https://github.com/lstein/Perl-GD/commit/67b163713c6c78dfeb693da0978ae934e5cd8210.patch - https://metacpan.org/release/RURBAN/GD-2.86/changes external
https://metacpan.org/release/RURBAN/GD-2.86/changes - http://www.openwall.com/lists/oss-security/2026/06/14/4 external
http://www.openwall.com/lists/oss-security/2026/06/14/4 - https://lists.debian.org/debian-lts-announce/2026/06/msg00027.html external
https://lists.debian.org/debian-lts-announce/2026/06/msg00027.html - CVE-2026-11526 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-11526
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Sun Jun 14 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/