This issue affects RawTherapee: through 5.11.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/RawTherapee/RawTherapee/pull/7359 |
|
Tue, 27 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rawtherapee
Rawtherapee rawtherapee |
|
| Vendors & Products |
Rawtherapee
Rawtherapee rawtherapee |
Tue, 27 Jan 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Integer Overflow or Wraparound vulnerability in RawTherapee (rtengine modules). This vulnerability is associated with program files dcraw.Cc. This issue affects RawTherapee: through 5.11. | |
| Title | A possible integer overflow vulnerability in RawTherapee/RawTherapee | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GovTech CSG
Published:
Updated: 2026-01-27T20:44:34.832Z
Reserved: 2026-01-27T08:39:10.281Z
Link: CVE-2026-24808
Updated: 2026-01-27T20:44:31.145Z
Status : Deferred
Published: 2026-01-27T09:15:51.023
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-24808
No data.
OpenCVE Enrichment
Updated: 2026-04-18T02:30:15Z