Code execution via mismatched XWD pixel metadata
Published Apr 18, 2026 · Updated Apr 18, 2026
Heap buffer overflow in the XWD codec in HappySeaFox SAIL before commit 36aa5c7 allows remote attackers to execute arbitrary code. xwd_private_read_pixels resolves a one-byte indexed pixel buffer from pixmap_depth but casts it to uint32_t when attacker-controlled bits_per_pixel is 32, reading and writing four bytes per pixel. Processing a crafted XWD image is the required gate; the demonstrated overwrite corrupts adjacent heap memory, while arbitrary code execution is the advisory's bounded worst-case impact.
Summary
What happened
Heap buffer overflow in the XWD codec in HappySeaFox SAIL before commit 36aa5c7 allows remote attackers to execute arbitrary code. xwd_private_read_pixels resolves a one-byte indexed pixel buffer from pixmap_depth but casts it to uint32_t when attacker-controlled bits_per_pixel is 32, reading and writing four bytes per pixel. Processing a crafted XWD image is the required gate; the demonstrated overwrite corrupts adjacent heap memory, while arbitrary code execution is the advisory's bounded worst-case impact.
The record
- CVE
- CVE-2026-40492
- Published
- Apr 18, 2026
- Updated
- Apr 18, 2026
- Vendor
- HappySeaFox
- Product
- SAIL
- Classifications
- CWE-787, T1203
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Apr 18, 2026CVE publishedPublication date reported by the CVE source.
- Apr 18, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=< 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- GHSA-526v-vm72-4v64 crafted XWD proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo