Heap-based buffer overflow in kitty - CVE-2026-33633
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in the load_image_data() function in kitty/graphics.c when processing a PNG-format Kitty graphics protocol command whose payload exceeds the resized buffer capacity. A remote attacker can send a specially crafted graphics protocol command to cause a denial of service.
User interaction is required to process the malicious terminal input.
Affected software
Debian Linux
kitty (Debian package)
How to mitigate CVE-2026-33633
kitty (Debian package) - update to 0.41.1-2+deb13u1