{"id":"CVE-2026-24808","summary":"A  possible integer overflow vulnerability in RawTherapee/RawTherapee","details":"Integer Overflow or Wraparound vulnerability in RawTherapee (rtengine modules). This vulnerability is associated with program files dcraw.Cc.\n\nThis issue affects RawTherapee: through 5.11.","modified":"2026-08-12T03:51:24.045056626Z","published":"2026-01-27T08:44:58.065Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24808.json","cna_assigner":"GovTech CSG","cwe_ids":["CWE-190"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24808.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24808"},{"type":"FIX","url":"https://github.com/RawTherapee/RawTherapee/pull/7359"},{"type":"PACKAGE","url":"https://github.com/RawTherapee/RawTherapee"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rawtherapee/rawtherapee","events":[{"introduced":"0"},{"fixed":"db575c6690d30ce6428c0e1383bec8b8f1fb8d21"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"5.11"},{"fixed":"5.11"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["5.11-rc1","5.10","5.10-rc1","5.9","5.9-rc1","5.7","pre-dev-github-actions","nightly-github-actions","5.4","5.4-rc3","5.4-rc2","5.4-rc1","5.2","5.0-r1-gtk3","5.0-gtk3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24808.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/S:P/AU:Y/R:U/V:C/RE:M/U:Amber"}]}