

FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
Published:
13 January 2026 at 23:00:00
Alert date:
14 January 2026 at 18:00:46
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
FreeImage version 3.18.0 contains a Use After Free vulnerability in the PluginTARGA.cpp file, specifically in the loadRLE() function. This memory corruption vulnerability could potentially allow attackers to execute arbitrary code or cause application crashes when processing malicious TARGA image files. The vulnerability has been documented with proof-of-concept code available on GitHub. Use After Free vulnerabilities are particularly dangerous as they can lead to remote code execution in applications that process untrusted image files. Organizations using FreeImage library should assess their exposure and consider updating or implementing mitigations.
Technical details
Mitigation steps:
Affected products:
FreeImage
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-70968
https://github.com/MiracleWolf/FreeimageCrash/tree/main
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.

