Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2026-33633— Kitty has a Heap Buffer Overflow in its Graphics Protocol Handler

CVSS 7.5 · High EPSS 0.04% · P12

Affected Version Matrix 1

VendorProductVersion RangeStatus
kovidgoyalkitty< 0.47.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-33633

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kitty has a Heap Buffer Overflow in its Graphics Protocol Handler
Source: NVD (National Vulnerability Database)
Vulnerability Description
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a PNG format declaration (f=100) whose payload exceeds twice the initial buffer capacity. The overflow is attacker-controlled in both length and content, causing DoS and potentially escalation to RCE itself. This issue has been fixed in version 0.47.0.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
堆缓冲区溢出
Source: NVD (National Vulnerability Database)
Vulnerability Title
KiTTY 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
KiTTY是一个轻量级的telnet和WindowsSSH客户端。 Kitty 0.46.2及之前版本存在安全漏洞,该漏洞源于load_image_data()中堆缓冲区溢出,允许写入终端stdin的进程通过APC图形协议命令触发崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
kovidgoyalkitty < 0.47.0 -

II. Public POCs for CVE-2026-33633

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 8108 chars
Paid plan includes:
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-33633

登录查看更多情报信息。
Advisory · 1Patch · 1

IV. Related Vulnerabilities

V. Comments for CVE-2026-33633

No comments yet


Leave a comment