A vulnerability, which was classified as critical, has been found in GIMP. The impacted element is the function decode_lzss of the component PAA File Format Plugin. Performing a manipulation results in out-of-bounds write.

This vulnerability is identified as CVE-2026-6695. The attack can be initiated remotely. There is not any exploit available.