CVE-2026-33633
published 2026-05-19CVE-2026-33633: Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can…
PriorityP349high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.37%
29.4th percentile
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a PNG format declaration (f=100) whose payload exceeds twice the initial buffer capacity. The overflow is attacker-controlled in both length and content, causing DoS and potentially escalation to RCE itself. This issue has been fixed in version 0.47.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kovidgoyal | kitty | < 0.47.0 | 0.47.0 |
| ubuntu | kitty | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
kitty vulnerabilities
vendor_ubuntu·2026-06-17·CVSS 8.8
CVE-2026-33642 [HIGH] kitty vulnerabilities
Title: kitty vulnerabilities
Summary: Several security issues were fixed in kitty.
It was discovered that kitty incorrectly handled certain image data. An
attacker able to write to the terminal's input could possibly use this
issue to cause kitty to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-33633)
It was discovered that kitty incorrectly handled certain graphics commands.
An attacker able to write escape sequences to a kitty terminal could
possibly use this issue to cause kitty to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-33642)
Instructions: After a standard system update you need to restart kitty to make all the
necessary changes.
VulDB
kovidgoyal kitty up to 0.46.x load_image_data heap-based overflow (GHSA-j68c-v8x4-269g)
vuldb·2026-05-19·CVSS 7.5
CVE-2026-33633 [HIGH] kovidgoyal kitty up to 0.46.x load_image_data heap-based overflow (GHSA-j68c-v8x4-269g)
A vulnerability categorized as critical has been discovered in kovidgoyal kitty up to 0.46.x. This vulnerability affects the function load_image_data. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability appears as CVE-2026-33633. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-33633 kitty: Kitty: Remote Code Execution via crafted APC graphics protocol command
bugzilla·2026-05-19·CVSS 7.5
CVE-2026-33633 [HIGH] CVE-2026-33633 kitty: Kitty: Remote Code Execution via crafted APC graphics protocol command
CVE-2026-33633 kitty: Kitty: Remote Code Execution via crafted APC graphics protocol command
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a PNG format declaration (f=100) whose payload exceeds twice the initial buffer capacity. The overflow is attacker-controlled in both length and content, causing DoS and potentially escalation to RCE itself. This issue has been fixed in version 0.47.0.
Bugzilla
CVE-2026-33633 kitty: Kitty: Remote Code Execution via crafted APC graphics protocol command [epel-all]
bugzilla·2026-05-19·CVSS 7.5
CVE-2026-33633 [HIGH] CVE-2026-33633 kitty: Kitty: Remote Code Execution via crafted APC graphics protocol command [epel-all]
CVE-2026-33633 kitty: Kitty: Remote Code Execution via crafted APC graphics protocol command [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
2026-05-19
Published