Skip to content
CVE-2026-101203 - Exploits & Severity

CVE-2026-101203 - Exploits & Severity

Feedly • September 28, 2026

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119)

An out-of-bounds write vulnerability in the 1bpp RLE Decoder component of FastStone Image Viewer up to version 8.3 allows remote attackers to write data beyond allocated memory boundaries.

An unauthenticated attacker can trigger this vulnerability remotely by sending a specially crafted image file that requires user interaction to open, potentially allowing memory corruption that could compromise the application's integrity and availability.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

No patch information available.

Update FastStone Image Viewer to a version newer than 8.3 when available. Until a patch is released, avoid opening image files from untrusted sources. Consider using alternative image viewers or disabling the application if not essential to business operations. The vendor has been contacted but has not provided a response or patch timeline.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Feedly found the first article mentioning CVE-2026-101203 . See article

NVD published the first details for CVE-2026-101203

A CVSS base score of 6.3 has been assigned.

GitHub Advisories released a security advisory .

FastStone Image Viewer 1bpp RLE Decoder out-of-bounds writeA vulnerability ha...

Be the first to know critical vulnerabilities

Collect, analyze, and vulnerability reports faster using AI