CVE-2026-11526

EUVD-2026-36659
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle.

GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "cmd |") or begins with a redirect ("> path", ">> path") is run as a command or redirect rather than opened as a file. _make_filehandle is the single open path behind every filename-accepting constructor (new, newFromPng, newFromJpeg, and the rest); the in-memory *Data variants do not open a path and are unaffected.

Any caller that forwards untrusted input to one of these constructors as a pathname can run an arbitrary command or truncate a file under the process UID.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Debian logo
Debian Releases
Debian Product
Codename
libgd-perl
bookworm
2.76-4+deb12u1
fixed
bookworm (security)
2.76-4+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
2.73-1+deb11u1
fixed
forky
2.84-3
fixed
sid
2.84-3
fixed
trixie
2.78-1+deb13u1
fixed
trixie (security)
2.78-1+deb13u1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-GD
Amazon Linux 2
0:2.49-3.amzn2.0.3
fixed
Amazon Linux 2023
0:2.80-1.amzn2023.0.3
fixed
perl-GD-debuginfo
Amazon Linux 2
0:2.49-3.amzn2.0.3
fixed
Amazon Linux 2023
0:2.80-1.amzn2023.0.3
fixed
perl-GD-debugsource
Amazon Linux 2023
0:2.80-1.amzn2023.0.3
fixed